Sceawere

Vulnerability Detail

CVE-2026-72897UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenSSL Out-of-Bounds Write Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
9h ago
Vendor
OpenSSL
Product
OpenSSL
Attack Type
CWE-787 Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-29T16:17:09.903Z",
  "pubdate": "2026-09-29T16:17:09.903Z",
  "executiveSummary": "This vulnerability is an out-of-bounds write (CWE-787) within OpenSSL, specifically triggered when an application invokes SSL_set_SSL_CTX() mid-handshake to switch the connection context. The issue arises from a stale state representation where an internal array responsible for tracking certificate validity slots is sized based on the initial SSL_CTX configuration rather than the updated one.\nA remote attacker can exploit this discrepancy if the replacement SSL_CTX contains more provider signature algorithms than the original. By sending a crafted TLS 1.3 handshake containing specific signature algorithms, an attacker can trigger an out-of-bounds memory read and a fixed-value out-of-bounds write on the server heap. This memory corruption can lead to heap metadata damage, resulting in process termination and a Denial of Service (DoS).\nThe vulnerability is assessed as Low severity, primarily because it requires specific, non-default configurations—such as the use of separate library contexts or heterogeneous providers—and would typically prevent legitimate clients from successfully negotiating affected algorithms. Authentication is not required for exploitation, as the flaw is reachable during the TLS handshake process over a network.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper management of certificate validity flag arrays during context migration in the TLS handshake. When an OpenSSL connection is initialized, it allocates an internal array to track certificate validity. The size of this array is determined by the number of built-in certificate types plus the number of provider TLS-SIGALG entries known to the initial SSL_CTX.\nThe vulnerability is triggered when an application calls SSL_set_SSL_CTX() during a handshake—a common practice in SNI (Server Name Indication) callbacks to switch virtual hosts. The current implementation fails to re-evaluate or resize the internal array when the SSL_CTX is replaced. If the new SSL_CTX supports a larger number of provider signature algorithms than the original, the indexing logic for these algorithms becomes misaligned.\nThe attack flow proceeds as follows: 1) The client initiates a TLS 1.3 handshake with a server. 2) The server performs an SSL_set_SSL_CTX() call to switch to a context with a larger set of provider signature algorithms. 3) The server parses the client's signature algorithms extension. 4) Because the internal array size is derived from the stale (original) context's capabilities, the parser attempts to map the new signature algorithms to slot indices that exceed the allocated boundary of the array.\nWhen an index exceeds the array bounds, the server performs an out-of-bounds read of a four-byte word. If the value at that address is zero, the logic proceeds to write a fixed value over that memory location. By providing a sequence of signature algorithms, an attacker can perform multiple writes, eventually corrupting the heap metadata structures associated with the process heap. This corruption typically triggers a segmentation fault or a memory abort, resulting in a Denial of Service.\nExploitation is restricted to TLS 1.3, as provider signature algorithms are not utilized in earlier versions. Furthermore, the mismatch must be significant enough to cause index overflows. If a provider signature algorithm is not recognized by the replacement context, it is discarded, preventing further processing. Consequently, the conditions for exploitation are narrow, requiring specific configuration disparities between library contexts or providers, such as the difference between the OpenSSL default provider and the FIPS provider regarding SM2 support."
}
CVE-2026-72897: OpenSSL Out-of-Bounds Write Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere