Segmentation fault in SSL_check_chain
Published Apr 21, 2020
7.5
HIGHCVSS 3.1
EPSS 53.34%
Description
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
Affected products
-
- Version Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f)StatusaffectedConstraints-
- Version
Configuration 2
- 9.0
- 10.0
Configuration 4
- 30
- 31
- 32
Configuration 5
- 12.1.3
- 13.4.0.0
- 13.3.0.0
- 13.4.0.0
- 12.4.0
- 12.2.1.4.0
- a9.4
- ≤ 5.6.48
- ≥ 5.7.0 · ≤ 5.7.30
- ≥ 8.0.0 · ≤ 8.0.20
- ≤ 8.0.20
- ≤ 4.0.12
- ≥ 8.0.0 · ≤ 8.0.20
- ≤ 8.0.21
- 8.56
- 8.57
- 8.58
- 8.59
Configuration 6
- ≥ 7.3
- ≥ 9.5
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 8
- < 9.2.5.0
Configuration 9
- < 6.0.9
No data.
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 5
openssl097a
Not affected
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Linux 8
compat-openssl10
Not affected
Red Hat Enterprise Linux 8
openssl
Not affected
Red Hat JBoss Core Services
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
openssl
Not affected
Red Hat JBoss Web Server 3
openssl
Not affected
Red Hat JBoss Web Server 5
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | openssl | Not affected | n/a |
| Red Hat JBoss Core Services | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Not affected | n/a |
| Red Hat JBoss Web Server 3 | openssl | Not affected | n/a |
| Red Hat JBoss Web Server 5 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw was introduced by the following OpenSSL commit: https://github.com/openssl/openssl/commit/5235ef44b93306a14d0b6c695b13c64b16e1fdec which was shipped as a part of OpenSSL-1.1.1d, therefore older versions are not affected by this flaw. OpenSSL packages shipped with Red Hat Products are NOT affected by this flaw. The affected `signature_algorithm_cert` check which causes the flaw is only applied to TLS 1.3, therefore older versions of TLS are not be affected by this flaw. Also, the vulnerable `SSL_check_chain()` is not called directly from libssl, but may be used by the application inside a callback (e.g., client_hello or cert callback) to verify that a candidate certificate chain will be acceptable to the client. Thus, applications that use openssl without invoking the `SSL_check_chain()` function are not vulnerable to this flaw. Lastly, no Red Hat Middleware products ship the affected version of OpenSSL. However, some components, such as Netty and Wildfly, may be configured by customers to use any OpenSSL version. Customers who have configured their setups to use a vulnerable version of OpenSSL are advised to upgrade to the latest unaffected version immediately.
Red Hat mitigation
Applications compiled with OpenSSL >= 1.1.1d that either use openssl without invoking the `SSL_check_chain()` function or do not use TLS 1.3 are not vulnerable to this flaw.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (54 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 53.34% (0.53336) | 98.96th | v5 (v2026.06.15) |
| Jun 15, 2026 | 53.34% (0.53336) | 98.84th | v5 (v2026.06.15) |
| Apr 20, 2026 | 60.77% (0.60769) | 98.30th | v4 (v2025.03.14) |
| Mar 23, 2026 | 67.31% (0.67307) | 98.54th | v4 (v2025.03.14) |
| Mar 4, 2026 | 64.69% (0.64688) | 98.43th | v4 (v2025.03.14) |
| Mar 1, 2026 | 54.33% (0.54325) | 97.98th | v4 (v2025.03.14) |
| Feb 18, 2026 | 64.69% (0.64688) | 98.41th | v4 (v2025.03.14) |
| Feb 4, 2026 | 67.31% (0.67307) | 98.52th | v4 (v2025.03.14) |
| Feb 1, 2026 | 54.33% (0.54325) | 97.96th | v4 (v2025.03.14) |
| Jan 4, 2026 | 67.31% (0.67307) | 98.50th | v4 (v2025.03.14) |
| Jan 1, 2026 | 53.56% (0.53563) | 97.90th | v4 (v2025.03.14) |
| Dec 4, 2025 | 67.31% (0.67307) | 98.48th | v4 (v2025.03.14) |
| Dec 1, 2025 | 54.33% (0.54325) | 97.91th | v4 (v2025.03.14) |
| Nov 21, 2025 | 66.69% (0.66690) | 98.46th | v4 (v2025.03.14) |
| Nov 18, 2025 | 53.88% (0.53882) | 97.90th | v4 (v2025.03.14) |
| Nov 4, 2025 | 66.69% (0.66690) | 98.46th | v4 (v2025.03.14) |
| Nov 1, 2025 | 53.56% (0.53563) | 97.87th | v4 (v2025.03.14) |
| Oct 4, 2025 | 66.69% (0.66690) | 98.48th | v4 (v2025.03.14) |
| Oct 1, 2025 | 53.56% (0.53563) | 97.92th | v4 (v2025.03.14) |
| Sep 4, 2025 | 67.22% (0.67225) | 98.51th | v4 (v2025.03.14) |
| Sep 1, 2025 | 53.15% (0.53148) | 97.90th | v4 (v2025.03.14) |
| Aug 4, 2025 | 67.22% (0.67225) | 98.48th | v4 (v2025.03.14) |
| Aug 1, 2025 | 53.72% (0.53720) | 97.90th | v4 (v2025.03.14) |
| Jul 16, 2025 | 66.69% (0.66690) | 98.43th | v4 (v2025.03.14) |
| Jul 4, 2025 | 63.13% (0.63134) | 98.28th | v4 (v2025.03.14) |
| Jul 1, 2025 | 49.46% (0.49457) | 97.67th | v4 (v2025.03.14) |
| Jun 4, 2025 | 63.13% (0.63134) | 98.26th | v4 (v2025.03.14) |
| Jun 1, 2025 | 49.46% (0.49457) | 97.66th | v4 (v2025.03.14) |
| May 6, 2025 | 63.13% (0.63134) | 98.26th | v4 (v2025.03.14) |
| May 4, 2025 | 60.28% (0.60277) | 98.14th | v4 (v2025.03.14) |
| May 1, 2025 | 49.46% (0.49457) | 97.64th | v4 (v2025.03.14) |
| Mar 30, 2025 | 60.80% (0.60802) | 98.13th | v4 (v2025.03.14) |
| Mar 29, 2025 | 73.14% (0.73143) | 98.41th | v4 (v2025.03.14) |
| Mar 28, 2025 | 60.80% (0.60802) | 98.13th | v4 (v2025.03.14) |
| Mar 27, 2025 | 73.14% (0.73143) | 98.67th | v4 (v2025.03.14) |
| Mar 20, 2025 | 65.88% (0.65884) | 98.41th | v4 (v2025.03.14) |
| Mar 19, 2025 | 72.76% (0.72760) | 98.67th | v4 (v2025.03.14) |
| Mar 17, 2025 | 65.41% (0.65408) | 98.34th | v4 (v2025.03.14) |
| Dec 17, 2024 | 19.27% (0.19274) | 96.27th | v3 (v2023.03.01) |
| Mar 12, 2024 | 8.10% (0.08103) | 94.13th | v3 (v2023.03.01) |
| Nov 8, 2023 | 9.95% (0.09953) | 94.27th | v3 (v2023.03.01) |
| Aug 25, 2023 | 30.48% (0.30482) | 96.38th | v3 (v2023.03.01) |
| May 8, 2023 | 33.99% (0.33995) | 96.43th | v3 (v2023.03.01) |
| Mar 28, 2023 | 6.15% (0.06151) | 92.39th | v3 (v2023.03.01) |
| Mar 7, 2023 | 6.46% (0.06461) | 92.56th | v3 (v2023.03.01) |
| Mar 6, 2023 | 35.45% (0.35455) | 97.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 35.45% (0.35455) | 96.81th | v2 (v2022.01.01) |
| Feb 3, 2022 | 28.23% (0.28233) | 96.46th | v1 |
| Oct 21, 2021 | 28.23% (0.28233) | 98.38th | v1 |
| Sep 1, 2021 | 27.61% (0.27609) | 98.38th | v1 |
| Jul 21, 2021 | 27.61% (0.27609) | 0.00th | v1 |
| Jun 15, 2021 | 26.97% (0.26975) | 0.00th | v1 |
| Jun 3, 2021 | 26.33% (0.26329) | 0.00th | v1 |
| Apr 14, 2021 | 25.67% (0.25672) | 0.00th | v1 |
References (45)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/157527/OpenSSL-signature_algorithms_cert-Denial-Of-Service.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/May/5 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/04/22/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-1967 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1823670 Issue Tracking
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=eb563247aef3e83dda7679c43f9649270462e5b1 x_refsource_CONFIRM
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=eb563247aef3e83dda7679c43f9649270462e5b1
- https://github.com/advisories/GHSA-jq65-29v4-4x35 Advisory
- https://github.com/irsl/CVE-2020-1967 x_refsource_MISCExploitThird Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44440 x_refsource_CONFIRMThird Party Advisory
- https://lists.apache.org/thread.html/r66ea9c436da150683432db5fbc8beb8ae01886c6459ac30c2cea7345%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r66ea9c436da150683432db5fbc8beb8ae01886c6459ac30c2cea7345@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r94d6ac3f010a38fccf4f432b12180a13fa1cf303559bd805648c9064%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r94d6ac3f010a38fccf4f432b12180a13fa1cf303559bd805648c9064@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r9a41e304992ce6aec6585a87842b4f2e692604f5c892c37e3b0587ee%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9a41e304992ce6aec6585a87842b4f2e692604f5c892c37e3b0587ee@%3Cdev.tomcat.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/
- https://nvd.nist.gov/vuln/detail/CVE-2020-1967
- https://rustsec.org/advisories/RUSTSEC-2020-0015.html
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:11.openssl.asc vendor-advisoryx_refsource_FREEBSDPatchThird Party Advisory
- https://security.gentoo.org/glsa/202004-10 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200424-0003/ x_refsource_CONFIRMThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200717-0004/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-1967
- https://www.debian.org/security/2020/dsa-4661 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.openssl.org/news/secadv/20200421.txt x_refsource_CONFIRMVendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_20_05 x_refsource_CONFIRMThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_20_05_OpenSSL x_refsource_CONFIRMThird Party Advisory
- https://www.tenable.com/security/tns-2020-03 x_refsource_CONFIRMThird Party Advisory
- https://www.tenable.com/security/tns-2020-04 x_refsource_CONFIRMThird Party Advisory
- https://www.tenable.com/security/tns-2020-11 x_refsource_CONFIRMThird Party Advisory
- https://www.tenable.com/security/tns-2021-10 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.