Sceawere
Vulnerability Detail
CVE-2026-75805UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OpenSSL CMP NULL Pointer Dereference
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 9h ago
- Vendor
- OpenSSL
- Product
- OpenSSL
- Attack Type
- CWE-476 NULL-pointer dereference
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-29T16:17:11.063Z",
"pubdate": "2026-09-29T16:17:11.063Z",
"executiveSummary": "This vulnerability involves a NULL pointer dereference (CWE-476) within the OpenSSL CMP (Certificate Management Protocol) client implementation.\nThe issue specifically affects CMP clients utilizing PKCS#10 CSRs (Certificate Signing Requests) to request certificate revocation.\nThe vulnerability leads to an abnormal termination (crash) of the client application, resulting in a Denial of Service (DoS).\nExploitation requires an attacker to act as a malicious or compromised CMP server, or a man-in-the-middle capable of bypassing message protection mechanisms.\nThe vulnerability is restricted to the specific code path handling PKCS#10 CSR revocation requests; clients using alternate identification methods, such as direct certificate reference or issuer/serial number identification, remain unaffected.\nFIPS modules are not impacted as the CMP implementation resides outside the FIPS module boundary.",
"technicalDetails": "The root cause of the vulnerability lies in the improper handling of server-provided identification data during a CMP Revocation Request (RR) session when the request is initiated via a PKCS#10 CSR.\nWhen a CMP client initiates a revocation request using OSSL_CMP_exec_RR_ses() with a CSR supplied via OSSL_CMP_CTX_set1_p10CSR(), the client does not possess the issuer name or serial number of the target certificate, as these fields are absent from a standard PKCS#10 CSR structure.\nUpon receiving a revocation response from a CMP server, the client attempts to validate the response. The protocol allows the server to optionally include the name of the revoked certificate. The client logic attempts to compare the server-provided identity against the identity it used to initiate the request.\nBecause the PKCS#10 CSR method lacks issuer/serial information, the local pointer intended to reference this identity is NULL. When the client logic proceeds to evaluate the server's response, it performs a read operation on this uninitialized or NULL pointer, triggering a segmentation fault/dereference error and crashing the process.\nThe attack flow requires the attacker to successfully pass message protection checks, meaning the attacker must be a server in possession of the legitimate shared secret or trust anchor. Once message protection is validated, the attacker sends a maliciously crafted revocation response containing a spoofed or specific certificate name. The client's attempt to reconcile this name against the non-existent local identifier leads to the immediate invocation of a NULL pointer, forcing an abnormal process termination.\nThis vulnerability is localized to the CMP client-side logic. It is not remotely exploitable in scenarios where message protection is robustly implemented and the server remains untrusted or unauthorized. However, in environments where a client interacts with a compromised infrastructure, the exploit is deterministic and reliably triggers a DoS state."
}