---
schema_version: '1.0'
id: security-20260705-d43447
url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-22796
url_hash: d43447b978ca3c9f13e4cdbaeb045a9be9f2e82fb051ec71dfc67542888b8f06
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-22796
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2026-22796
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- openssl
- Debian
lang: en
published_at: '2026-01-27T16:16:35Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-05T15:35:57Z'
status: published
content_hash: a423453f05fb720972d59b758f5f25bfd549031efe5327d14011c9623ad35034
license_note: full
summary: 'Issue summary: A type confusion vulnerability exists in the signature verification
  of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first
  validating the type, causing an invalid or NULL pointer dereference when processing
  malformed PKCS#7 data.  Impact su'
summary_source: rss
summary_en: 'Issue summary: A type confusion vulnerability exists in the signature
  verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without
  first validating the type, causing an invalid or NULL pointer dereference when processing
  malformed PKCS#7 data.  Impact su'
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2026-22796 — openssl
---

# DEBIAN-CVE-2026-22796 — openssl

## TL;DR
Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact su

## Key Points
- cve / DEBIAN-CVE-2026-22796 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L / openssl / Debian

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
**Advisory:** DEBIAN-CVE-2026-22796

**Affected (your watchlist):**
- `Debian:openssl` 3.0.11-1~deb12u2 → no fixed version listed [rpi]

**Details:**
Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2026-22796

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2026-22796_

## Source
元記事: [DEBIAN-CVE-2026-22796 — openssl](https://osv.dev/vulnerability/DEBIAN-CVE-2026-22796) — published 2026-01-27T16:16:35Z
