Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.
Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.
The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.
Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity.
The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.
OpenSSL 1.0.2 is not affected by this issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade opensslUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-perl | Feb 3, 2026 | Jan 28, 2026 |
| Alpine Linux | — | Upgrade openssl | Jan 28, 2026 | Jan 27, 2026 |
| Amazon Linux Ami 2 | — | Upgrade edk2-toolsUpgrade openssl11-libsUpgrade openssl11-staticUpgrade openssl-snapsafe-debuginfoUpgrade edk2-aarch64Upgrade openssl-snapsafe-libsUpgrade openssl-staticUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-snapsafe-develUpgrade opensslUpgrade edk2-debuginfoUpgrade openssl11-debuginfoUpgrade edk2-tools-docUpgrade openssl-snapsafe-staticUpgrade openssl-snapsafe-perlUpgrade openssl-debuginfoUpgrade openssl11Upgrade openssl-snapsafeUpgrade openssl-libsUpgrade openssl11-develUpgrade edk2-ovmf | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-fips-provider-latest-debuginfoUpgrade aws-cfn-bootstrapUpgrade openssl-perlUpgrade openssl-snapsafe-libs-debuginfoUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-libs-debuginfoUpgrade openssl-develUpgrade openssl-fips-provider-latestUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade openssl-snapsafe-libs | Feb 20, 2026 | Jan 27, 2026 |
| Debian | — | Upgrade openssl | Jan 29, 2026 | Jan 29, 2026 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Apr 29, 2026 | Apr 28, 2026 |
| Freebsd | — | Upgrade openssl36Upgrade openssl35Upgrade FreeBSDUpgrade openssl33Upgrade openssl34Upgrade openssl | Jan 28, 2026 | Jan 27, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Jan 27, 2026 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory46 | Mar 10, 2026 | Mar 9, 2026 |
| Oracle_linux | — | Upgrade openssl-develUpgrade opensslUpgrade openssl-libsUpgrade openssl-perl | Jan 30, 2026 | Jan 27, 2026 |
| Redhat_linux | — | Upgrade openssl-libsUpgrade openssl-debuginfoNo solution existsUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-debugsourceUpgrade opensslUpgrade openssl-libs-debuginfo | Jan 29, 2026 | Jan 27, 2026 |
| Rocky_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-libsUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade openssl-develUpgrade openssl-debugsource | Feb 2, 2026 | Jan 30, 2026 |
| Ubuntu | — | Upgrade opensslUpgrade libssl1.0.0 (Ubuntu Pro)Upgrade libssl3Upgrade libssl1.1 (Ubuntu Pro)Upgrade openssl1.0 (Ubuntu Pro)Upgrade openssl (Ubuntu Pro)Upgrade libssl3t64 | Jan 28, 2026 | Jan 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub