CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption
Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.
Other sources
Possible NULL Dereference in Password-Based CMS Decryption
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 20240524git3e722403cd16-18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.3.7-3 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 1.0.2zq - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 1.1.1zh - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 3.0.21 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 3.4.6 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 3.5.7 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 3.6.3 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 4.0.1
Event History
Frequently Asked Questions
What is the significance of CVE-2026-42766?
CVE-2026-42766 is a vulnerability that can lead to a NULL pointer dereference during password-based CMS decryption in OpenSSL.
What is the severity rating of CVE-2026-42766?
CVE-2026-42766 has a medium severity rating of 5.9 according to the CVSS 3.1 scoring system.
How can I mitigate CVE-2026-42766 in my system?
To mitigate CVE-2026-42766, ensure that you update OpenSSL to a version that includes the fix for this vulnerability.
Who is affected by CVE-2026-42766?
CVE-2026-42766 affects users of OpenSSL, specifically those utilizing password-based encryption for CMS messages.
Is there a workaround for CVE-2026-42766?
Currently, the best approach for CVE-2026-42766 is to apply the vendor's security updates, as there are no known effective workarounds.