Out-of-bounds write in OpenSSL - CVE-2026-72897

 

Out-of-bounds write in OpenSSL - CVE-2026-72897

Published: September 30, 2026


Vulnerability identifier: #VU152959
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72897
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in TLS certificate validity flag handling when processing peer signature algorithms after SSL_set_SSL_CTX() changes the connection context during a handshake. A remote attacker can offer provider signature algorithms to cause a denial of service.

The replacement context must know about more provider signature algorithms than the original context, and the affected algorithms are usable only with TLS 1.3.


Affected software

OpenSSL
Debian Linux
openssl (Debian package)

How to mitigate CVE-2026-72897

Install security update from vendor's website.

OpenSSL - addressed in versions 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3
openssl (Debian package) - update to 3.5.7-1~deb13u3

External References

Related Security Bulletins