---
schema_version: '1.0'
id: security-20260705-ee8746
url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-35188
url_hash: ee8746c11a03ead54849d2ba42f4356ffc143f3ca70852f70d4b5cf6c03f2486
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-35188
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2026-35188
- severity:CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
- openssl
- Debian
lang: en
published_at: '2026-06-09T17:17:05Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-05T15:36:30Z'
status: published
content_hash: ab48e1cc96d823b80b7c0a9f62e44356b1b373fd85fd830e7029ff4a9b9f22ef
license_note: full
summary: 'Issue summary: A malicious server can exploit TLS OCSP stapling by delivering
  a crafted response through the status_request extension, triggering a double-free
  in the client''s certificate verification path.  Impact summary: Successful exploitation
  allows an attacker to corrupt he'
summary_source: rss
summary_en: 'Issue summary: A malicious server can exploit TLS OCSP stapling by delivering
  a crafted response through the status_request extension, triggering a double-free
  in the client''s certificate verification path.  Impact summary: Successful exploitation
  allows an attacker to corrupt he'
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2026-35188 — openssl
---

# DEBIAN-CVE-2026-35188 — openssl

## TL;DR
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.  Impact summary: Successful exploitation allows an attacker to corrupt he

## Key Points
- cve / DEBIAN-CVE-2026-35188 / severity:CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L / openssl / Debian

## Details
**Severity:** CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
**Advisory:** DEBIAN-CVE-2026-35188

**Affected (your watchlist):**
- `Debian:openssl` 3.0.11-1~deb12u2 → no fixed version listed [rpi]

**Details:**
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.  Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a double-free, potentially leading to a Denial of Service or possibly an attacker controlled code execution or other undefined behavior.  If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked.  The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2026-35188

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2026-35188_

## Source
元記事: [DEBIAN-CVE-2026-35188 — openssl](https://osv.dev/vulnerability/DEBIAN-CVE-2026-35188) — published 2026-06-09T17:17:05Z
