Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension.
Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible.
CWE: CWE-476: NULL Pointer Dereference
Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA).
When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or servers that don't support raw public keys may be able to complete a TLS connection by pinning or verifying the corresponding certificate or its public key.
Deployments that prefer to configure just a private key with no certificate need to upgrade to an updated release as noted below.
FIPS impact: no
No FIPS modules are affected by this issue, as the SSL protocol implementation is outside the OpenSSL FIPS module boundary.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Aug 26, 2026 | Aug 25, 2026 |
| Debian | — | Upgrade openssl | Aug 26, 2026 | Aug 26, 2026 |
| Freebsd | — | Upgrade FreeBSDUpgrade openssl40Upgrade opensslUpgrade openssl34Upgrade openssl36Upgrade openssl35 | Aug 26, 2026 | Aug 25, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Aug 27, 2026 | Aug 25, 2026 |
| Redhat_linux | — | Upgrade openssl-perlUpgrade openssl-libsUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-debugsourceUpgrade openssl-libs-debuginfoUpgrade openssl-devel | Aug 27, 2026 | Aug 25, 2026 |
| Rocky_linux | — | Upgrade openssl-libsUpgrade openssl-develUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-debugsourceUpgrade openssl-perl | Sep 17, 2026 | Sep 15, 2026 |
| Ubuntu | — | Upgrade libssl3Upgrade libssl3t64Upgrade openssl | Aug 26, 2026 | Aug 25, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 21, 2026 | Aug 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub