CVE-2026-28388

HIGH EPSS 54.7%
Published Apr 7, 20262mo ago · Modified Jun 17, 20262w ago
7.5 CVSS 3.1
High
Find Similar
Published Apr 7, 2026 2mo ago
Last Modified Jun 17, 2026 2w ago

Description

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS Details

Base Score
7.5
Exploitability
3.9
Impact
3.6
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
54.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 7

VendorProductVersionRange
opensslopenssl*≥1.0.2  –  <1.0.2zp
opensslopenssl*≥1.1.1  –  <1.1.1zg
opensslopenssl*≥3.0.0  –  <3.0.20
opensslopenssl*≥3.3.0  –  <3.3.7
opensslopenssl*≥3.4.0  –  <3.4.5
opensslopenssl*≥3.5.0  –  <3.5.6
opensslopenssl*≥3.6.0  –  <3.6.2

References 8

  • cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-032379.html
  • cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-265688.html
  • github.com https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e
    Patch
  • github.com https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139
    Patch
  • github.com https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3
    Patch
  • github.com https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8
    Patch
  • github.com https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726
    Patch
  • openssl-library.org https://openssl-library.org/news/secadv/20260407.txt
    Vendor Advisory

Remediation

  • github.com https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e
    Patch
  • github.com https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139
    Patch
  • github.com https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3
    Patch
  • github.com https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8
    Patch
  • github.com https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726
    Patch