Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.
Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.
When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.
Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Apr 10, 2026 | Apr 7, 2026 |
| Amazon Linux Ami 2 | — | Upgrade openssl-debuginfoUpgrade openssl-staticUpgrade edk2-toolsUpgrade edk2-debuginfoUpgrade openssl-snapsafe-perlUpgrade openssl-snapsafe-libsUpgrade openssl-develUpgrade openssl11-staticUpgrade openssl11-develUpgrade openssl-snapsafe-develUpgrade openssl-snapsafe-debuginfoUpgrade edk2-aarch64Upgrade openssl-libsUpgrade openssl11Upgrade edk2-ovmfUpgrade openssl-snapsafeUpgrade openssl-snapsafe-staticUpgrade openssl-perlUpgrade openssl11-debuginfoUpgrade opensslUpgrade openssl11-libsUpgrade edk2-tools-doc | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-develUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-fips-provider-latest-debuginfoUpgrade openssl-libsUpgrade openssl-perlUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-libs-debuginfoUpgrade openssl-debugsourceUpgrade openssl-fips-provider-latestUpgrade openssl-snapsafe-libs | Apr 14, 2026 | Apr 7, 2026 |
| Debian | — | Upgrade openssl | Apr 9, 2026 | Apr 9, 2026 |
| Freebsd | — | Upgrade openssl35Upgrade opensslUpgrade openssl111Upgrade openssl34Upgrade openssl36 | Apr 8, 2026 | Apr 7, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Apr 9, 2026 | Apr 7, 2026 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory47 | May 6, 2026 | May 4, 2026 |
| Oracle Missing Cpu Jul 2026 | — | Apply the July 2026 Critical Patch Update (CPU) for Oracle Database | Jul 22, 2026 | Apr 7, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Apr 7, 2026 |
| Splunk | — | Upgrade Splunk Universal Forwarder to version 10.2.6Upgrade Splunk Universal Forwarder to version 10.2.5Upgrade Splunk Universal Forwarder to version 9.4.14Upgrade Splunk Universal Forwarder to version 10.4.1Upgrade Splunk Universal Forwarder to version 9.4.13Upgrade Splunk Universal Forwarder to version 10.0.8Upgrade Splunk Universal Forwarder to version 10.0.9Upgrade Splunk Universal Forwarder to version 10.4.2 | Jul 30, 2026 | Apr 7, 2026 |
| Ubuntu | — | Upgrade opensslUpgrade openssl (Ubuntu Pro)Upgrade libssl1.0.0 (Ubuntu Pro)Upgrade openssl1.0 (Ubuntu Pro)Upgrade libssl3t64Upgrade libssl3Upgrade libssl1.1 (Ubuntu Pro) | Apr 9, 2026 | Apr 8, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Apr 7, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub