CVE-2026-14457: RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate

Published Aug 25, 2026
·
Updated

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signaturealgorithmscert" TLS extension.

Other sources

RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate

— Microsoft

Affected Software

6 affected componentsFixes available
OpenSSL OpenSSL=
debian/openssl<=3.5.6-1~deb13u2, <=3.6.3-1
1.1.1w-0+deb11u11.1.1w-0+deb11u83.0.20-1~deb12u23.5.7-1~deb13u23.6.4-1
OpenSSL OpenSSL>=3.4.0<3.4.7
OpenSSL OpenSSL>=3.5.0<3.5.8
OpenSSL OpenSSL>=3.6.0<3.6.4
OpenSSL OpenSSL>=4.0.0<4.0.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u8Fixed in 3.0.20-1~deb12u2Fixed in 3.5.7-1~deb13u2Fixed in 3.6.4-1
  2. Configuration

    Avoid key-only RPK configuration by configuring a corresponding certificate along with the matching private key; when the certificate is configured, the "signature_algorithms_cert" extension is handled reliably even without the fix.

    RFC7250 Raw Public Keys (RPK) configuration Certificate associated with the locally configured private key = Always configure a corresponding certificate (possibly self-signed or signed by any convenient CA)

Event History

Aug 25, 2026
CVE Published
via MITRE·12:58 PM
Data Sourced
via MITRE·12:58 PM
DescriptionWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
RemedyAffected Software
Data Sourced
via Ubuntu·07:09 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·07:11 PM
Description
Aug 26, 2026
Data Sourced
via Debian·07:12 PM
DescriptionAffected Software
Aug 27, 2026
Data Sourced
via Microsoft·08:12 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Server or client deployments with RFC7250 Raw Public Keys enabled are exposed when they configure only a local private key and no associated certificate. Configurations that pair the private key with a matching certificate handle the relevant TLS extension reliably even without the fix.

2

What must a remote peer do to trigger the denial of service?

The peer must solicit raw public keys and send the normally omitted "signature_algorithms_cert" TLS extension. Under the affected key-only RPK configuration, this can cause the application to abort.

3

What can be done if the fix cannot be deployed immediately?

Configure a matching certificate for the locally configured private key. The certificate may be self-signed or signed by a convenient CA; this also may allow peers without RPK support to connect by pinning or verifying the certificate or its public key.

4

How can an operator determine whether a deployment is at risk?

Review TLS configuration for RFC7250 RPK use and check whether the local identity consists only of a private key without a corresponding certificate. Such a deployment is at risk if it accepts connections from peers that can request RPKs and supply the "signature_algorithms_cert" extension.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203