Intel

AIKIDO-2026-983127

openssl is vulnerable to NULL Pointer Dereference

NULL Pointer DereferenceCVE-2026-14457 Published 6 days ago

37

Low Risk

This Affects:

C++openssl
3.4.0 - 3.4.6
Fixed in 3.4.7
3.5.0 - 3.5.7
Fixed in 3.5.8
3.6.0 - 3.6.3
Fixed in 3.6.4
4.0.0 - 4.0.1
Fixed in 4.0.2
Are you affected? Scan for Free

TL;DR

OpenSSL selects a signature algorithm for a raw public key configuration from the peer signature_algorithms_cert extension. When only a private key is configured and no certificate is attached, that selection reads a missing certificate pointer and aborts the process. The fix requires a certificate before it reads that pointer.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you enable raw public keys with a private key and no certificate.

Background info

openssl is vulnerable to NULL Pointer Dereference in versions 3.4.0 - 3.4.6, 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.

How to fix this

Upgrade the openssl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform