Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.
Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.
When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.
Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.
The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Apr 10, 2026 | Apr 7, 2026 |
| Amazon Linux Ami 2 | — | Upgrade edk2-aarch64Upgrade openssl-snapsafe-debuginfoUpgrade edk2-debuginfoUpgrade openssl-develUpgrade openssl-debuginfoUpgrade openssl-snapsafeUpgrade openssl-libsUpgrade openssl11-debuginfoUpgrade openssl-snapsafe-libsUpgrade openssl-staticUpgrade openssl-snapsafe-develUpgrade edk2-tools-docUpgrade openssl11Upgrade openssl11-staticUpgrade openssl-snapsafe-staticUpgrade opensslUpgrade edk2-ovmfUpgrade openssl-perlUpgrade edk2-toolsUpgrade openssl11-libsUpgrade openssl-snapsafe-perlUpgrade openssl11-devel | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-libs-debuginfoUpgrade openssl-libsUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-perlUpgrade openssl-fips-provider-latestUpgrade openssl-fips-provider-latest-debuginfoUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-snapsafe-libs | Apr 14, 2026 | Apr 7, 2026 |
| Debian | — | Upgrade openssl | Apr 9, 2026 | Apr 9, 2026 |
| Freebsd | — | Upgrade opensslUpgrade openssl111Upgrade openssl34Upgrade openssl36Upgrade openssl35 | Apr 8, 2026 | Apr 7, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Apr 9, 2026 | Apr 7, 2026 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory47 | May 6, 2026 | May 4, 2026 |
| Oracle Missing Cpu Jul 2026 | — | Apply the July 2026 Critical Patch Update (CPU) for Oracle Database | Jul 22, 2026 | Apr 7, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Apr 7, 2026 |
| Splunk | — | Upgrade Splunk Universal Forwarder to version 10.0.9Upgrade Splunk Universal Forwarder to version 10.4.1Upgrade Splunk Universal Forwarder to version 10.2.6Upgrade Splunk Universal Forwarder to version 10.4.2Upgrade Splunk Universal Forwarder to version 9.4.14Upgrade Splunk Universal Forwarder to version 10.0.8Upgrade Splunk Universal Forwarder to version 10.2.5Upgrade Splunk Universal Forwarder to version 9.4.13 | Jul 30, 2026 | Apr 7, 2026 |
| Ubuntu | — | Upgrade libssl1.1 (Ubuntu Pro)Upgrade libssl3Upgrade libssl1.0.0 (Ubuntu Pro)Upgrade libssl3t64Upgrade openssl (Ubuntu Pro)Upgrade opensslUpgrade openssl1.0 (Ubuntu Pro) | Apr 9, 2026 | Apr 8, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Apr 7, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub