The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values implemented in libcrypto perform this check. Therefore, where a purpose is set the certificate chain will still be rejected even when the strict flag has been used. A purpose is set by default in libssl client and server certificate verification routines, but it can be overridden or removed by an application. In order to be affected, an application must explicitly set the X509_V_FLAG_X509_STRICT verification flag and either not set a purpose for the certificate verification or, in the case of TLS client or server applications, override the default purpose. OpenSSL versions 1.1.1h and newer are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1h-1.1.1j).
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-develUpgrade opensslUpgrade openssl-libsUpgrade openssl-perl | May 4, 2022 | Mar 25, 2021 |
| Alpine Linux | — | Upgrade opensslUpgrade openssl1.1-compatUpgrade openssl3 | Jun 17, 2022 | Mar 25, 2021 |
| Amazon Linux Ami 2 | — | Upgrade openssl11Upgrade edk2-debuginfoUpgrade openssl11-debuginfoUpgrade edk2-tools-pythonUpgrade openssl11-libsUpgrade edk2-toolsUpgrade openssl11-staticUpgrade edk2-ovmfUpgrade edk2-aarch64Upgrade edk2-tools-docUpgrade openssl11-devel | Mar 29, 2021 | Mar 25, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 25, 2021 |
| Centos_linux | — | Upgrade openssl-libsUpgrade openssl-debuginfoUpgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-libs-debuginfoUpgrade opensslUpgrade openssl-perl | Mar 31, 2021 | Mar 25, 2021 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Mar 25, 2021 |
| Freebsd | — | Upgrade node12Upgrade FreeBSDUpgrade node14Upgrade nodeUpgrade mariadb104-serverUpgrade mariadb105-serverUpgrade mariadb103-serverUpgrade node10Upgrade mysql57-serverUpgrade opensslUpgrade mysql80-server | Jul 20, 2021 | Jul 20, 2021 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Apr 1, 2021 | Mar 25, 2021 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 26, 2021 | Mar 25, 2021 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.9 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Oct 12, 2021 |
| Oracle Solaris | — | Upgrade runtime/nodejs/nodejs-12 to version 12.22.1-11.4.36.0.1.101.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.25-11.4.36.0.1.101.0 on Solaris 11.4Upgrade runtime/nodejs/nodejs-14 to version 14.17.0-11.4.36.0.1.101.0 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.36.0.1.101.0 on Solaris 11.4Upgrade library/security/openssl-11 to version 1.1.1.11-11.4.35.0.1.94.2 on Solaris 11.4Upgrade runtime/nodejs to version 14.17.0-11.4.36.0.1.101.0 on Solaris 11.4 | Jul 21, 2021 | Mar 25, 2021 |
| Oracle_linux | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade opensslUpgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-static | Mar 30, 2021 | Mar 25, 2021 |
| Redhat_linux | — | Upgrade openssl-debugsourceUpgrade openssl-develUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-libsUpgrade openssl-perl | Mar 31, 2021 | Mar 25, 2021 |
| Rocky_linux | — | Upgrade openssl-develUpgrade openssl-libsUpgrade openssl-perlUpgrade openssl-debugsourceUpgrade openssl-libs-debuginfoUpgrade opensslUpgrade openssl-debuginfo | Mar 12, 2024 | Mar 25, 2021 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.11 or later | Sep 22, 2025 | Jul 16, 2021 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Jul 15, 2021 |
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen7 to version 7.0.1-R1456 or later | May 25, 2026 | Jul 16, 2021 |
| Suse | — | Upgrade libopenssl1_1-32bitUpgrade nodejs12-develUpgrade nodejs10Upgrade libopenssl1_1Upgrade libopenssl-1_1-develUpgrade nodejs10-docsUpgrade libopenssl1_1-hmac-32bitUpgrade nodejs12Upgrade nodejs12-docsUpgrade libopenssl1_1-hmacUpgrade openssl-1_1Upgrade nodejs10-develUpgrade npm10Upgrade npm12 | Jul 15, 2021 | Mar 25, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 25, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub