The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values implemented in libcrypto perform this check. Therefore, where a purpose is set the certificate chain will still be rejected even when the strict flag has been used. A purpose is set by default in libssl client and server certificate verification routines, but it can be overridden or removed by an application. In order to be affected, an application must explicitly set the X509_V_FLAG_X509_STRICT verification flag and either not set a purpose for the certificate verification or, in the case of TLS client or server applications, override the default purpose. OpenSSL versions 1.1.1h and newer are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1h-1.1.1j).
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-develUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl | May 4, 2022 | Mar 25, 2021 |
| Alpine Linux | — | Upgrade openssl3Upgrade openssl1.1-compatUpgrade openssl | Jun 17, 2022 | Mar 25, 2021 |
| Amazon Linux Ami 2 | — | Upgrade openssl11Upgrade edk2-debuginfoUpgrade openssl11-debuginfoUpgrade edk2-tools-pythonUpgrade openssl11-libsUpgrade edk2-tools-docUpgrade edk2-ovmfUpgrade edk2-toolsUpgrade openssl11-staticUpgrade edk2-aarch64Upgrade openssl11-devel | Mar 29, 2021 | Mar 25, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 25, 2021 |
| Centos_linux | — | Upgrade openssl-develUpgrade openssl-debuginfoUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade openssl | Mar 31, 2021 | Mar 25, 2021 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Mar 25, 2021 |
| Freebsd | — | Upgrade mariadb103-serverUpgrade FreeBSDUpgrade nodeUpgrade mariadb104-serverUpgrade node12Upgrade node14Upgrade mariadb105-serverUpgrade opensslUpgrade mysql57-serverUpgrade mysql80-serverUpgrade node10 | Jul 20, 2021 | Jul 20, 2021 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Apr 1, 2021 | Mar 25, 2021 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 26, 2021 | Mar 25, 2021 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.9 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017. | Jun 25, 2025 | Oct 12, 2021 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.36.0.1.101.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.25-11.4.36.0.1.101.0 on Solaris 11.4Upgrade runtime/nodejs to version 14.17.0-11.4.36.0.1.101.0 on Solaris 11.4Upgrade runtime/nodejs/nodejs-14 to version 14.17.0-11.4.36.0.1.101.0 on Solaris 11.4Upgrade library/security/openssl-11 to version 1.1.1.11-11.4.35.0.1.94.2 on Solaris 11.4Upgrade runtime/nodejs/nodejs-12 to version 12.22.1-11.4.36.0.1.101.0 on Solaris 11.4 | Jul 21, 2021 | Mar 25, 2021 |
| Oracle_linux | — | Upgrade openssl-perlUpgrade openssl-libsUpgrade opensslUpgrade openssl-staticUpgrade openssl-develUpgrade openssl-debugsource | Mar 30, 2021 | Mar 25, 2021 |
| Redhat_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfo | Mar 31, 2021 | Mar 25, 2021 |
| Rocky_linux | — | Upgrade openssl-debugsourceUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-libs-debuginfoUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-perl | Mar 12, 2024 | Mar 25, 2021 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.11 or later | Sep 22, 2025 | Jul 16, 2021 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Jul 15, 2021 |
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen7 to version 7.0.1-R1456 or later | May 25, 2026 | Jul 16, 2021 |
| Suse | — | Upgrade libopenssl1_1-32bitUpgrade nodejs10-docsUpgrade nodejs12-docsUpgrade libopenssl-1_1-develUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_1Upgrade nodejs12-develUpgrade nodejs10Upgrade nodejs12Upgrade nodejs10-develUpgrade openssl-1_1Upgrade libopenssl1_1-hmacUpgrade npm12Upgrade npm10 | Jul 15, 2021 | Mar 25, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 25, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub