Junglewise Threat Intelligence

CVE-2026-28387: OpenSSL use-after-free in DANE TLSA-based authentication

CVE-2026-28387 · Severity: high · CVSS 8.1 · Published 2026-04-07

Technologies: Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, OpenSSL, Siemens SIMATIC CN 4100. Vendors: Siemens, OpenSSL.

Executive brief

OpenSSL is a widely used security library that enables encrypted communications for websites and email servers. A vulnerability exists in how certain clients verify server identities using DANE TLSA records, which could allow an attacker to crash the application or potentially execute malicious code. This issue primarily affects specialized configurations; standard email (SMTP) clients following common security standards are generally not at risk.

Technical details

A use-after-free and double-free vulnerability exists in OpenSSL's 'dane_match_cert' function within 'crypto/x509/x509_vfy.c'. The root cause is the use of 'OPENSSL_free' instead of 'X509_free' on an X509 object, leading to incorrect reference counting and memory management. The vulnerability is triggered when a client using DANE TLSA-based authentication encounters a server publishing a TLSA RRset containing both PKIX-TA(0)/PKIX-EE(1) and DANE-TA(2) certificate usages. Successful exploitation could lead to data corruption, denial of service, or arbitrary code execution. The issue is patched in OpenSSL versions 3.6.2, 3.5.6, 3.4.5, 3.3.7, and 3.0.20.

Affected products

  • OpenSSL OpenSSL 3.6.0 to 3.6.1, 3.5.0 to 3.5.5, 3.4.0 to 3.4.4, 3.3.0 to 3.3.6, 3.0.0 to 3.0.19
  • Siemens SIMATIC CN 4100 < V5.0
  • Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem All versions

Timeline

  • 2026-03-05: patched: Fixes merged into OpenSSL source code.
  • 2026-04-07: advisory: OpenSSL Security Advisory published.
  • 2026-04-07: disclosed: CVE-2026-28387 published.

References

Related threats