---
schema_version: '1.0'
id: security-20260705-83dabe
url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-42766
url_hash: 83dabee4448d7e2f785879b9440fe62795596556740aaa4778dcf8f90f8c710a
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-42766
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2026-42766
- severity:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- openssl
- Debian
lang: en
published_at: '2026-06-09T17:17:07Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-05T15:36:30Z'
status: published
content_hash: be088576f10ec8241152bda74bda82292bd642b015fcb592185a3b52ae3ae971
license_note: full
summary: 'Issue summary: A specially crafted password-encrypted CMS message can trigger
  a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer
  dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgori'
summary_source: rss
summary_en: 'Issue summary: A specially crafted password-encrypted CMS message can
  trigger a NULL pointer dereference during CMS decryption.  Impact summary: This
  NULL pointer dereference leads to an application crash and a Denial of Service.  The
  CMS PasswordRecipientInfo.keyDerivationAlgori'
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2026-42766 — openssl
---

# DEBIAN-CVE-2026-42766 — openssl

## TL;DR
Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgori

## Key Points
- cve / DEBIAN-CVE-2026-42766 / severity:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H / openssl / Debian

## Details
**Severity:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
**Advisory:** DEBIAN-CVE-2026-42766

**Affected (your watchlist):**
- `Debian:openssl` 3.0.11-1~deb12u2 → no fixed version listed [rpi]

**Details:**
Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2026-42766

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2026-42766_

## Source
元記事: [DEBIAN-CVE-2026-42766 — openssl](https://osv.dev/vulnerability/DEBIAN-CVE-2026-42766) — published 2026-06-09T17:17:07Z
