NULL pointer dereference in OpenBSD - #VU126141
Published: April 15, 2026
OpenBSD
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in RPKI client within the x509_get_time() function in /cvs/src/usr.sbin/rpki-client/x509.c. A remote attacker with control over a malicious RRDP Publication Server can send specially crafted response to the client and perform a denial of service attack.