Intel

AIKIDO-2026-74354

openssl is vulnerable to NULL Pointer Dereference

NULL Pointer DereferenceCVE-2026-63076 Published 6 days ago

55

Medium Risk

This Affects:

C++openssl
3.0.0 - 3.0.21
Fixed in 3.0.22
3.4.0 - 3.4.6
Fixed in 3.4.7
3.5.0 - 3.5.7
Fixed in 3.5.8
3.6.0 - 3.6.3
Fixed in 3.6.4
4.0.0 - 4.0.1
Fixed in 4.0.2
Are you affected? Scan for Free

TL;DR

CMP password based MAC verification reads the protectionAlg parameter and, when the pointer is not NULL, casts it to a PBM parameter without checking the ASN.1 type. A message whose parameter has a different type makes that cast follow an invalid pointer and crashes a CMP server that accepts password based protection, or a CMP client checking a response. The fix checks the parameter type before it uses the value.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application uses CMP with password based message protection.

Background info

openssl is vulnerable to NULL Pointer Dereference in versions 3.0.0 - 3.0.21, 3.4.0 - 3.4.6, 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.

How to fix this

Upgrade the openssl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform