Out-of-bounds read in OpenSSL - CVE-2026-42771
Published: June 10, 2026
OpenSSL
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in X509_VERIFY_PARAM_set1_email() when validating a crafted email address. A remote attacker can supply a crafted email address to cause a denial of service.
The bug is reachable via S/MIME validation with a crafted From: address.