← All Advisories

OpenSSL NULL pointer dereference in delta CRL Number extension processing causes denial of service

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-28388

Key Details

CVECVE-2026-28388
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-07-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsopenssl openssl
Classified asCWE-476 (NULL Pointer Dereference)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
opensslopenssl
SubsystemsGeneral OT
SectorsMultiple

What to Know

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension

is processed a NULL pointer dereference might happen if the required CRL

Number extension is missing.

Impact summary: A NULL pointer dereference can trigger a crash which

leads to a Denial of Service for an application.

When CRL processing and delta CRL processing is enabled during X.509

certificate verification, the delta CRL processing does not check

whether the CRL Number extension is NULL before dereferencing it.

When a malformed delta CRL file is being processed, this parameter

can be NULL, causing a NULL pointer dereference.

Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in

the verification context, the certificate being verified to contain a

freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and

an attacker to provide a malformed CRL to an application that processes it.

The vulnerability is limited to Denial of Service and cannot be escalated to

achieve code execution or memory disclosure. For that reason the issue was

assessed as Low severity according to our Security Policy.

The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,

as the affected code is outside the OpenSSL FIPS module boundary. (NVD)

What to Do

Monitor openssl's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-28388
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-28388
Vendor advisoryhttps://openssl-library.org/news/secadv/20260407.txt