Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.
Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.
When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.
Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.
The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Apr 10, 2026 | Apr 7, 2026 |
| Amazon Linux Ami 2 | — | Upgrade edk2-ovmfUpgrade openssl-snapsafe-develUpgrade openssl11-staticUpgrade edk2-tools-docUpgrade opensslUpgrade openssl-snapsafe-staticUpgrade openssl11-libsUpgrade openssl11Upgrade openssl-perlUpgrade openssl11-develUpgrade edk2-toolsUpgrade openssl-snapsafe-perlUpgrade openssl11-debuginfoUpgrade openssl-develUpgrade edk2-debuginfoUpgrade openssl-debuginfoUpgrade edk2-aarch64Upgrade openssl-snapsafe-libsUpgrade openssl-staticUpgrade openssl-libsUpgrade openssl-snapsafeUpgrade openssl-snapsafe-debuginfo | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-libs-debuginfoUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-fips-provider-latest-debuginfoUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-snapsafe-libsUpgrade openssl-fips-provider-latest | Apr 14, 2026 | Apr 7, 2026 |
| Debian | — | Upgrade openssl | Apr 9, 2026 | Apr 9, 2026 |
| Freebsd | — | Upgrade openssl111Upgrade opensslUpgrade openssl34Upgrade openssl35Upgrade openssl36 | Apr 8, 2026 | Apr 7, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Apr 9, 2026 | Apr 7, 2026 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory47 | May 6, 2026 | May 4, 2026 |
| Oracle Missing Cpu Jul 2026 | — | Apply the July 2026 Critical Patch Update (CPU) for Oracle Database | Jul 22, 2026 | Apr 7, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Apr 7, 2026 |
| Splunk | — | Upgrade Splunk Universal Forwarder to version 9.4.14Upgrade Splunk Universal Forwarder to version 10.2.5Upgrade Splunk Universal Forwarder to version 10.0.8Upgrade Splunk Universal Forwarder to version 9.4.13Upgrade Splunk Universal Forwarder to version 10.2.6Upgrade Splunk Universal Forwarder to version 10.4.1Upgrade Splunk Universal Forwarder to version 10.4.2Upgrade Splunk Universal Forwarder to version 10.0.9 | Jul 30, 2026 | Apr 7, 2026 |
| Ubuntu | — | Upgrade openssl1.0 (Ubuntu Pro)Upgrade libssl3t64Upgrade libssl1.0.0 (Ubuntu Pro)Upgrade openssl (Ubuntu Pro)Upgrade opensslUpgrade libssl3Upgrade libssl1.1 (Ubuntu Pro) | Apr 9, 2026 | Apr 8, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Apr 7, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub