Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.
Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.
However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.
By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.
The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.
No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Apr 10, 2026 | Apr 7, 2026 |
| Amazon Linux Ami 2 | — | Upgrade openssl11-libsUpgrade edk2-aarch64Upgrade edk2-ovmfUpgrade edk2-toolsUpgrade openssl11-develUpgrade edk2-tools-docUpgrade openssl11Upgrade openssl11-staticUpgrade openssl11-debuginfoUpgrade edk2-debuginfo | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-libsUpgrade openssl-debugsourceUpgrade openssl-develUpgrade openssl-fips-provider-latestUpgrade openssl-perlUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-debuginfoUpgrade openssl-snapsafe-libsUpgrade openssl-fips-provider-latest-debuginfoUpgrade openssl-libs-debuginfoUpgrade openssl | Apr 14, 2026 | Apr 7, 2026 |
| Debian | — | Upgrade openssl | Apr 9, 2026 | Apr 9, 2026 |
| Freebsd | — | Upgrade openssl111Upgrade openssl35Upgrade opensslUpgrade openssl34Upgrade openssl36 | Apr 8, 2026 | Apr 7, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Apr 9, 2026 | Apr 7, 2026 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory47 | May 6, 2026 | May 4, 2026 |
| Oracle Missing Cpu Jul 2026 | — | Apply the July 2026 Critical Patch Update (CPU) for Oracle Database | Jul 22, 2026 | Apr 7, 2026 |
| Redhat_linux | — | No solution exists | Sep 17, 2026 | Apr 7, 2026 |
| Ubuntu | — | Upgrade openssl (Ubuntu Pro)Upgrade libssl3t64Upgrade openssl1.0 (Ubuntu Pro)Upgrade opensslUpgrade libssl3Upgrade libssl1.1 (Ubuntu Pro)Upgrade libssl1.0.0 (Ubuntu Pro) | Apr 9, 2026 | Apr 8, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Apr 7, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub