NULL pointer dereference in OpenSSL - CVE-2026-75805
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in CMP client revocation response handling when processing a crafted response to a revocation request based on a PKCS#10 CSR. A remote user can send a crafted revocation response to cause a denial of service.
The response must pass message-protection validation, and clients identifying the certificate by a certificate or issuer and serial number are not affected.
Affected software
Debian Linux
openssl (Debian package)
How to mitigate CVE-2026-75805
openssl (Debian package) - update to 3.5.7-1~deb13u3