Junglewise Threat Intelligence

CVE-2025-69421: OpenSSL NULL pointer dereference in PKCS12_item_decrypt_d2i_ex

CVE-2025-69421 · Severity: high · CVSS 7.5 · Published 2026-01-27

Technologies: OpenSSL. Vendors: OpenSSL.

Executive brief

OpenSSL is a widely used security library that helps applications secure data and verify identities. A vulnerability exists where processing a specially crafted PKCS#12 file (often used for storing certificates and private keys) can cause the application to crash. This results in a denial-of-service, potentially disrupting business operations that rely on processing these files, though it does not allow for data theft or unauthorized access.

Technical details

A NULL pointer dereference vulnerability exists in the PKCS12_item_decrypt_d2i_ex() function of OpenSSL. The root cause is a failure to validate the 'oct' parameter before dereferencing it when called from PKCS12_unpack_p7encdata(). An attacker can exploit this by providing a malformed PKCS#12 file to an application that uses OpenSSL to process such files. Successful exploitation results in an immediate application crash (Denial of Service). The vulnerability is limited to DoS and does not permit remote code execution or memory disclosure. Patches are available in OpenSSL versions 3.6.1, 3.5.5, 3.4.4, 3.3.6, and 3.0.19.

Affected products

  • OpenSSL OpenSSL 3.6.0 before 3.6.1, 3.5.0 before 3.5.5, 3.4.0 before 3.4.4, 3.3.0 before 3.3.6, 3.0.0 before 3.0.19, 1.1.1 through 1.1.1ze, 1.0.2 through 1.0.2zn

Timeline

  • 2026-01-26: patched: Fixes committed to OpenSSL repository.
  • 2026-01-27: advisory: OpenSSL Security Advisory published.

References

Related threats