CVE-2026-63076: Invalid Pointer Dereference in CMP Server via Crafted protectionAlg

Published Aug 25, 2026
·
Updated

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.

Affected Software

2 affected components
OpenSSL OpenSSL
debian/openssl<=1.1.1w-0+deb11u1, <=1.1.1w-0+deb11u8, <=3.0.20-1~deb12u2, <=3.5.6-1~deb13u2, <=3.6.3-1

Event History

Aug 25, 2026
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeakness
Data Sourced
via Ubuntu·07:09 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·07:11 PM
DescriptionAffected Software
Data Sourced
via Launchpad·07:11 PM
Description

Frequently Asked Questions

1

Which deployments are exposed to this denial-of-service condition?

Applications acting as CMP servers are exposed if they accept PBM-protected CMP messages and PBM verification is reachable. CMP clients can also be affected when communicating with a malicious or intercepted CMP server.

2

Does an attacker need the PBM shared secret to trigger the issue?

No. The invalid parameter is processed during protection verification before any MAC is computed, so knowledge of the PBM shared secret is not required.

3

What kind of input triggers the crash?

The attacker must supply a CMP message whose protectionAlg parameter is present but has a type other than the expected PBMParameter. The affected verification path casts and dereferences that value without checking its ASN.1 type.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203