---
schema_version: '1.0'
id: security-20260705-44724c
url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-42767
url_hash: 44724cd874cb17109abe4f70bbe9d75f112172d344eddaba28b8c1415287f08c
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-42767
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2026-42767
- severity:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- openssl
- Debian
lang: en
published_at: '2026-06-09T17:17:08Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-05T15:36:30Z'
status: published
content_hash: cae4c9304b2ff81d2b5f6bb8c451cbfce0fa4b8dde9c9926f28b703ddd2f5177
license_note: full
summary: 'Issue summary: An attacker-controlled CMP (Certificate Management Protocol)
  server could trigger a NULL pointer dereference in a CMP client application.  Impact
  summary: A NULL pointer dereference causes a crash of the application and a Denial
  of Service.  An attacker controlling'
summary_source: rss
summary_en: 'Issue summary: An attacker-controlled CMP (Certificate Management Protocol)
  server could trigger a NULL pointer dereference in a CMP client application.  Impact
  summary: A NULL pointer dereference causes a crash of the application and a Denial
  of Service.  An attacker controlling'
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2026-42767 — openssl
---

# DEBIAN-CVE-2026-42767 — openssl

## TL;DR
Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling

## Key Points
- cve / DEBIAN-CVE-2026-42767 / severity:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H / openssl / Debian

## Details
**Severity:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
**Advisory:** DEBIAN-CVE-2026-42767

**Affected (your watchlist):**
- `Debian:openssl` 3.0.11-1~deb12u2 → no fixed version listed [rpi]

**Details:**
Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2026-42767

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2026-42767_

## Source
元記事: [DEBIAN-CVE-2026-42767 — openssl](https://osv.dev/vulnerability/DEBIAN-CVE-2026-42767) — published 2026-06-09T17:17:08Z
