Sceawere

Vulnerability Detail

CVE-2026-84783UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenSSL X.509 Cache Use-After-Free

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
9h ago
Vendor
OpenSSL
Product
OpenSSL
Attack Type
CWE-416 Use After Free
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-29T16:17:12.653Z",
  "pubdate": "2026-09-29T16:17:12.653Z",
  "executiveSummary": "A critical Use-After-Free (CWE-416) vulnerability exists in OpenSSL 4.0 related to the caching mechanism for X.509v3 certificate extensions.\nThe vulnerability allows a remote, unauthenticated attacker to trigger a crash in multi-threaded TLS clients or servers that perform certificate validation.\nThe flaw arises due to a race condition during the two-phase initialization of the extension cache, where multiple threads concurrently build and install cached data, leading to the premature freeing of memory currently in use by other threads.\nImpact is primarily a Denial of Service (DoS) resulting from memory corruption, specifically when concurrent connections initiate the first chain verification process using a shared trusted CA certificate.\nThe vulnerability affects OpenSSL 4.0. Users are advised to upgrade to version 4.0.3 to remediate the flaw. Legacy versions including 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2 are confirmed to be unaffected.\nThe FIPS module remains unaffected as X.509 certificate handling is excluded from the FIPS boundary.",
  "technicalDetails": "The vulnerability originates in the OpenSSL 4.0 X.509 extension caching logic. When an X.509 object requires its v3 extensions, the library performs a two-phase initialization process. First, the decoded values are computed while holding a read lock, and second, these results are committed to the cache under a write lock.\nThe root cause is an improper synchronization primitive usage. Because the initial read lock does not provide mutual exclusion, multiple threads can simultaneously compute the extension cache for the same X509 object. If multiple threads reach the write lock phase, each thread proceeds to install its own computed results into the cache. Crucially, the implementation does not verify if another thread has already committed data to the cache in the interim. Consequently, each thread effectively overwrites the previous results and invokes free() on the existing cached memory blocks.\nThis creates a classic Use-After-Free condition. If Thread A installs its cache and returns pointers to that data to its caller, and Thread B subsequently acquires the write lock to overwrite the cache, Thread B will free the memory addresses that Thread A is currently accessing. Any further attempt by Thread A to reference those pointers results in a read from deallocated memory, typically triggering a segmentation fault and crashing the process.\nThe scope of this vulnerability is limited to certificates shared across threads. In a TLS context, the primary vector is the collection of trusted CA certificates utilized for chain verification. These are globally cached and accessed by every connection. The first time multiple connections concurrently trigger the decoding of extensions for a specific trusted CA certificate, the race condition is initiated. Peer-supplied certificates are decoded in isolation per-connection and therefore do not contribute to this shared-memory conflict.\nExploitation requires no authentication or special privileges. An attacker simply needs to initiate multiple TLS handshakes simultaneously against a vulnerable multi-threaded TLS server or client that triggers the initial validation path for a shared certificate. By flooding the system at the exact moment the CA certificate's extensions are first cached, an attacker can reliably induce the use-after-free error, resulting in a system-wide Denial of Service."
}
CVE-2026-84783: OpenSSL X.509 Cache Use-After-Free (HIGH Severity, CVSS: 7.5) | Sceawere