Bug 2481890 (CVE-2026-42766) - CVE-2026-42766 openssl: Possible NULL Dereference in Password-Based CMS Decryption
Summary: CVE-2026-42766 openssl: Possible NULL Dereference in Password-Based CMS Decry...
Keywords:
Status: NEW
Alias: CVE-2026-42766
Deadline: 2026-06-09
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-27 14:18 UTC by OSIDB Bzimport
Modified: 2026-06-11 12:34 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:25237 0 None None None 2026-06-11 12:32:00 UTC
Red Hat Product Errata RHSA-2026:25239 0 None None None 2026-06-11 12:34:33 UTC

Description OSIDB Bzimport 2026-05-27 14:18:51 UTC
Possible NULL Dereference in Password-Based CMS Decryption

Possible NULL Dereference in Password-Based CMS Decryption (CVE-2026-42766)
Severity: Low

Issue summary: A specially crafted password-encrypted CMS message
can trigger a NULL pointer dereference during CMS decryption.

Impact summary: This NULL pointer dereference leads to an application crash
and a Denial of Service.

The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as
OPTIONAL in the ASN.1 specification and may therefore be absent in specially
crafted inputs. During the password-based CMS decryption the OpenSSL
CMS implementation dereferences this field without first checking whether it
was present.

An attacker who supplies such a CMS message to an application performing
password-based CMS decryption can trigger an application crash, leading to
a Denial of Service.

Applications that process password-encrypted CMS messages may be affected.

The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.

OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2 are vulnerable to this issue.

OpenSSL 4.0 users should upgrade to OpenSSL 4.0.1
OpenSSL 3.6 users should upgrade to OpenSSL 3.6.3.
OpenSSL 3.5 users should upgrade to OpenSSL 3.5.7.
OpenSSL 3.4 users should upgrade to OpenSSL 3.4.6.
OpenSSL 3.0 users should upgrade to OpenSSL 3.0.21.
OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zh
(premium support customers only).
OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zq
(premium support customers only).

This issue was reported by Mayank Jangid and Kushal Khemka on 20th April 2026,
independently reported by Hari Priandana on 4th May 2026, by Bhabani Sankar Das
on 15th May 2026, and by Qifan Zhang (Palo Alto Networks) on 18th May 2026.
The fix was developed by Igor Ustinov.

Comment 2 errata-xmlrpc 2026-06-11 12:32:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:25237 https://access.redhat.com/errata/RHSA-2026:25237

Comment 3 errata-xmlrpc 2026-06-11 12:34:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:25239 https://access.redhat.com/errata/RHSA-2026:25239


Note You need to log in before you can comment on or make changes to this bug.