CVE-2026-72897: Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
Issue summary: A TLS server that calls SSLsetSSLCTX() to switch a connection to a different SSLCTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSLsetSSLCTX() are not affected.
Other sources
Out-of-Bounds Access After SSLsetSSLCTX() During a Handshake
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u2Fixed in 3.0.22-1~deb12u1 - Compensating control
Avoid calling SSL_set_SSL_CTX() to replace a connection's SSL_CTX during a handshake; applications that never call SSL_set_SSL_CTX() are not affected.
Event History
Frequently Asked Questions
Which deployments are affected?
Only TLS servers that switch a connection to another SSL_CTX during the handshake by calling SSL_set_SSL_CTX() are affected. Applications that never call SSL_set_SSL_CTX() are not affected.
What condition makes the context switch unsafe?
The replacement SSL_CTX must know about more provider TLS signature algorithms than the SSL_CTX that originally created the connection. The connection retains the original certificate-slot count after the switch.
What does an attacker need to do, and what is the likely impact?
A remote peer may be able to trigger a small out-of-bounds read and, in some circumstances, a fixed-value out-of-bounds write on the server heap. The stated potential impact is denial of service.
How can I determine whether my application is exposed?
Review handshake-time code paths for calls to SSL_set_SSL_CTX(), including servername callbacks used to select a virtual host. For each such switch, determine whether the replacement context can have more provider signature algorithms than the original context.