The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values implemented in libcrypto perform this check. Therefore, where a purpose is set the certificate chain will still be rejected even when the strict flag has been used. A purpose is set by default in libssl client and server certificate verification routines, but it can be overridden or removed by an application. In order to be affected, an application must explicitly set the X509_V_FLAG_X509_STRICT verification flag and either not set a purpose for the certificate verification or, in the case of TLS client or server applications, override the default purpose. OpenSSL versions 1.1.1h and newer are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1h-1.1.1j).
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-develUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl | May 4, 2022 | Mar 25, 2021 |
| Alpine Linux | — | Upgrade opensslUpgrade openssl1.1-compatUpgrade openssl3 | Jun 17, 2022 | Mar 25, 2021 |
| Amazon Linux Ami 2 | — | Upgrade edk2-debuginfoUpgrade openssl11-debuginfoUpgrade edk2-tools-pythonUpgrade openssl11Upgrade edk2-ovmfUpgrade edk2-aarch64Upgrade edk2-toolsUpgrade openssl11-staticUpgrade openssl11-develUpgrade edk2-tools-docUpgrade openssl11-libs | Mar 29, 2021 | Mar 25, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 25, 2021 |
| Centos_linux | — | Upgrade openssl-libs-debuginfoUpgrade opensslUpgrade openssl-perlUpgrade openssl-debuginfoUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-debugsource | Mar 31, 2021 | Mar 25, 2021 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Mar 25, 2021 |
| Freebsd | — | Upgrade mariadb105-serverUpgrade node14Upgrade node12Upgrade mariadb104-serverUpgrade FreeBSDUpgrade nodeUpgrade mariadb103-serverUpgrade opensslUpgrade mysql80-serverUpgrade node10Upgrade mysql57-server | Jul 20, 2021 | Jul 20, 2021 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Apr 1, 2021 | Mar 25, 2021 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 26, 2021 | Mar 25, 2021 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.9 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Oct 12, 2021 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.36.0.1.101.0 on Solaris 11.4Upgrade library/security/openssl-11 to version 1.1.1.11-11.4.35.0.1.94.2 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.25-11.4.36.0.1.101.0 on Solaris 11.4Upgrade runtime/nodejs to version 14.17.0-11.4.36.0.1.101.0 on Solaris 11.4Upgrade runtime/nodejs/nodejs-14 to version 14.17.0-11.4.36.0.1.101.0 on Solaris 11.4Upgrade runtime/nodejs/nodejs-12 to version 12.22.1-11.4.36.0.1.101.0 on Solaris 11.4 | Jul 21, 2021 | Mar 25, 2021 |
| Oracle_linux | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade opensslUpgrade openssl-develUpgrade openssl-staticUpgrade openssl-debugsource | Mar 30, 2021 | Mar 25, 2021 |
| Redhat_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-libsUpgrade openssl-libs-debuginfoUpgrade openssl-debugsourceUpgrade openssl-develUpgrade openssl-debuginfo | Mar 31, 2021 | Mar 25, 2021 |
| Rocky_linux | — | Upgrade openssl-debugsourceUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-libs-debuginfoUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-libs | Mar 12, 2024 | Mar 25, 2021 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.11 or later | Sep 22, 2025 | Jul 16, 2021 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Jul 15, 2021 |
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen7 to version 7.0.1-R1456 or later | May 25, 2026 | Jul 16, 2021 |
| Suse | — | Upgrade nodejs10-develUpgrade libopenssl1_1-hmacUpgrade npm10Upgrade npm12Upgrade openssl-1_1Upgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_1Upgrade libopenssl-1_1-develUpgrade nodejs12-docsUpgrade nodejs12-develUpgrade nodejs10-docsUpgrade nodejs12Upgrade nodejs10Upgrade libopenssl1_1-32bit | Jul 15, 2021 | Mar 25, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 25, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub