CVE-2026-72897: Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake

Published Sep 29, 2026
·
Updated

Issue summary: A TLS server that calls SSLsetSSLCTX() to switch a connection to a different SSLCTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSLsetSSLCTX() are not affected.

Other sources

Out-of-Bounds Access After SSLsetSSLCTX() During a Handshake

— Debian

Affected Software

2 affected componentsFixes available
OpenSSL OpenSSL
debian/openssl<=3.5.7-1~deb13u2, <=3.6.4-1
3.0.20-1~deb12u23.0.22-1~deb12u1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 3.0.20-1~deb12u2Fixed in 3.0.22-1~deb12u1
  2. Compensating control

    Avoid calling SSL_set_SSL_CTX() to replace a connection's SSL_CTX during a handshake; applications that never call SSL_set_SSL_CTX() are not affected.

Event History

Sep 29, 2026
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Data Sourced
via Ubuntu·07:45 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·07:46 PM
DescriptionAffected Software
Data Sourced
via Launchpad·07:46 PM
Description

Frequently Asked Questions

1

Which deployments are affected?

Only TLS servers that switch a connection to another SSL_CTX during the handshake by calling SSL_set_SSL_CTX() are affected. Applications that never call SSL_set_SSL_CTX() are not affected.

2

What condition makes the context switch unsafe?

The replacement SSL_CTX must know about more provider TLS signature algorithms than the SSL_CTX that originally created the connection. The connection retains the original certificate-slot count after the switch.

3

What does an attacker need to do, and what is the likely impact?

A remote peer may be able to trigger a small out-of-bounds read and, in some circumstances, a fixed-value out-of-bounds write on the server heap. The stated potential impact is denial of service.

4

How can I determine whether my application is exposed?

Review handshake-time code paths for calls to SSL_set_SSL_CTX(), including servername callbacks used to select a virtual host. For each such switch, determine whether the replacement context can have more provider signature algorithms than the original context.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203