Executive brief
OpenSSL is a widely used security library that enables encrypted communications and digital signatures. A vulnerability in how it handles certain signed messages (PKCS#7 or S/MIME) could allow an attacker to crash a service or potentially execute unauthorized code. This occurs when a specially crafted message causes the system to mishandle memory during the signature verification process.
Technical details
A use-after-free vulnerability exists in the PKCS7_verify() function of OpenSSL. The root cause is the incorrect freeing of a caller-owned BIO object when the SignedData digestAlgorithms field in a PKCS#7 or S/MIME message is present as an empty ASN.1 SET. An attacker can trigger this by sending a specially crafted signed message to an application using the PKCS#7 APIs. If the application subsequently attempts to use or free the already-freed BIO, it results in memory corruption. This can lead to a Denial of Service (DoS) or potentially Remote Code Execution (RCE). Applications using the CMS APIs are not affected. Patches are available in versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, 3.0.21, 1.1.1zh, and 1.0.2zq.
Affected products
- OpenSSL Software Foundation OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, 1.0.2
Timeline
- 2026-04-27: disclosed: Reported by Thai Duong (Calif.io) in collaboration with Claude and Anthropic Research.
- 2026-06-09: advisory: Official OpenSSL security advisory published.
- 2026-06-09: patched
References
- https://github.com/openssl/security/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c
- https://github.com/openssl/security/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8
- https://github.com/openssl/security/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54
- https://github.com/openssl/security/commit/a541ae8bfe849a30cc885e8780715c0f488e496c
- https://github.com/openssl/security/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e
- https://openssl-library.org/news/secadv/20260609.txt