CVE-2026-75805: NULL Pointer Dereference in CMP Client Revocation Response Handling
Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.
Other sources
NULL Pointer Dereference in CMP Client Revocation Response Handling
— Debian
Affected Software
Event History
Frequently Asked Questions
Which CMP client workflows are exposed to this denial-of-service condition?
The affected workflow is certificate revocation where the client identifies the certificate using a PKCS#10 CSR rather than the certificate itself or an issuer name and serial number. This includes `openssl cmp -cmd rr -csr <file>` and API use of `OSSL_CMP_exec_RR_ses()` after supplying the CSR with `OSSL_CMP_CTX_set1_p10CSR()`.
What does an attacker need to trigger the crash?
The client must process a crafted CMP revocation response from a server. The crash occurs when the client sent a CSR, and the server returns a specially crafted certificate name for comparison.
Is every CMP revocation request affected?
No. The described condition depends on revocation requests that use a PKCS#10 CSR, which does not provide the issuer name and serial number the client would otherwise compare with the server response.
How can I determine whether my application is using the affected path?
Check whether it performs CMP revocation requests using `openssl cmp -cmd rr -csr <file>` or calls `OSSL_CMP_CTX_set1_p10CSR()` before `OSSL_CMP_exec_RR_ses()`. Those usages indicate that the client is taking the CSR-based revocation path described in the issue.