Heap Use-After-Free in the PKCS7_verify() Function
Published Jun 9, 2026
8.8
HIGHCVSS 3.1
EPSS 4.00%
Description
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.
Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.
When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.
In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.
Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.
The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
Affected products
-
Affected
- ≥ 1.0.2, < 1.0.2zq
- ≥ 1.1.1, < 1.1.1zh
- ≥ 3.0.0, < 3.0.21
- ≥ 3.4.0, < 3.4.6
- ≥ 3.5.0, < 3.5.7
- ≥ 3.6.0, < 3.6.3
- ≥ 4.0.0, < 4.0.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 1.0.2 · < 1.0.2zq
- ≥ 1.1.1 · < 1.1.1zh
- ≥ 3.0.0 · < 3.0.21
- ≥ 3.4.0 · < 3.4.6
- ≥ 3.5.0 · < 3.5.7
- ≥ 3.6.0 · < 3.6.3
- 4.0.0
No data.
Cost Management 4
costmanagement/costmanagement-metrics-rhel9-operator:1783539156
Fixed · RHSA-2026:39981
Red Hat Advanced Cluster Management for Kubernetes 2.13
rhacm2/console-rhel9:1785078581
Fixed · RHSA-2026:47737
Red Hat Discovery 2
discovery/discovery-server-rhel9:1782159791
Fixed · RHSA-2026:29197
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1782166952
Fixed · RHSA-2026:29197
Red Hat Enterprise Linux 10
openssl-1:3.5.5-4.el10_2
Fixed · RHSA-2026:25237
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
openssl-0:1.0.1e-61.el6_10.1
Fixed · RHSA-2026:66524
Red Hat Enterprise Linux 7 Extended Lifecycle Support
openssl-1:1.0.2k-26.el7_9.2
Fixed · RHSA-2026:58563
Red Hat Enterprise Linux 8
compat-openssl10-1:1.0.2o-4.el8_10.3
Fixed · RHSA-2026:36215
Red Hat Enterprise Linux 8
openssl-1:1.1.1k-16.el8_6
Fixed · RHSA-2026:26275
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
openssl-1:1.1.1k-16.el8_6
Fixed · RHSA-2026:26275
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
compat-openssl10-1:1.0.2o-4.el8_8.1
Fixed · RHSA-2026:36217
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
openssl-1:1.1.1k-16.el8_6
Fixed · RHSA-2026:26275
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
compat-openssl10-1:1.0.2o-4.el8_8.1
Fixed · RHSA-2026:36217
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
openssl-1:1.1.1k-16.el8_6
Fixed · RHSA-2026:26275
Red Hat Enterprise Linux 9
compat-openssl11-1:1.1.1k-5.el9_8.4
Fixed · RHSA-2026:44438
Red Hat Enterprise Linux 9
openssl-1:3.5.5-4.el9_8
Fixed · RHSA-2026:25239
Red Hat Enterprise Linux 9
openssl-1:3.5.5-4.el9_8
Fixed · RHSA-2026:25239
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
compat-openssl11-1:1.1.1k-4.el9_2.2
Fixed · RHSA-2026:39012
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
compat-openssl11-1:1.1.1k-5.el9_4.3
Fixed · RHSA-2026:39009
Red Hat Enterprise Linux 9.6 Extended Update Support
compat-openssl11-1:1.1.1k-5.el9_6.3
Fixed · RHSA-2026:35869
Red Hat Hardened Images
chunkah-main-0.6.0-3.hum1
Fixed · RHSA-2026:42825
Red Hat Hardened Images
openssl-main-3.5.8-0.1.hum1
Fixed · RHSA-2026:59641
Red Hat Hardened Images
openssl3-main-3.5.8-0.1.hum1
Fixed · RHSA-2026:59635
Red Hat Hardened Images
python-cryptography-main-50.0.0-1.hum1
Fixed · RHSA-2026:55543
Red Hat Hardened Images
ruby3-3-main-3.3.10-23.6.hum1
Fixed · RHSA-2026:62562
Red Hat Hardened Images
ruby3-4-main-3.4.10-31.7.hum1
Fixed · RHSA-2026:62790
Red Hat Hardened Images
ruby4-0-main-4.0.6-37.3.hum1
Fixed · RHSA-2026:62563
Red Hat Hardened Images
rust-bootupd-main-0.3.2-1.hum1
Fixed · RHSA-2026:67551
Red Hat Insights proxy 1.5
insights-proxy/insights-proxy-container-rhel9:1782890503
Fixed · RHSA-2026:34102
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202608241157-0
Fixed · RHSA-2026:59831
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-tp-rhel9:1787241211
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1781525684
Fixed · RHSA-2026:26319
Red Hat Update Infrastructure 5
rhui5/haproxy-rhel9:1781525671
Fixed · RHSA-2026:26319
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1781525693
Fixed · RHSA-2026:26319
Red Hat Update Infrastructure 5
rhui5/installer-tp-rhel9:1787135742
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1781525739
Fixed · RHSA-2026:26319
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
multicluster engine for Kubernetes 2.8
multicluster-engine/console-mce-rhel9:1785078604
Fixed · RHSA-2026:47735
Multicluster Engine for Kubernetes
multicluster-engine/hive-rhel9
Under investigation
Multicluster Engine for Kubernetes
multicluster-engine/hypershift-rhel9-operator
Under investigation
Red Hat Enterprise Linux 10
edk2
Not affected
Red Hat Enterprise Linux 10
shim
Not affected
Red Hat Enterprise Linux 10
shim-unsigned-aarch64
Not affected
Red Hat Enterprise Linux 10
shim-unsigned-x64
Not affected
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 7
shim-signed
Not affected
Red Hat Enterprise Linux 8
edk2
Not affected
Red Hat Enterprise Linux 8
mingw-openssl
Not affected
Red Hat Enterprise Linux 8
shim
Not affected
Red Hat Enterprise Linux 8
shim-unsigned-x64
Not affected
Red Hat Enterprise Linux 9
edk2
Not affected
Red Hat Enterprise Linux 9
shim
Not affected
Red Hat Enterprise Linux 9
shim-unsigned-aarch64
Not affected
Red Hat Enterprise Linux 9
shim-unsigned-x64
Not affected
Red Hat Hardened Images
netavark
Not affected
Red Hat Hardened Images
openshell
Not affected
Red Hat Hardened Images
rust
Not affected
Red Hat Hardened Images
rust-podman-sequoia
Not affected
Red Hat Hardened Images
unbound
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-openssl
Not affected
Red Hat JBoss Core Services
jbcs-openssl-win6-x86_64.zip
Not affected
Red Hat JBoss Web Server 6
jws-optional-native-components-win6-x86_64.zip
Not affected
Red Hat JBoss Web Server 7
jws-optional-native-components-win6-x86_64.zip
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Cost Management 4 | costmanagement/costmanagement-metrics-rhel9-operator:1783539156 | Fixed | RHSA-2026:39981 |
| Red Hat Advanced Cluster Management for Kubernetes 2.13 | rhacm2/console-rhel9:1785078581 | Fixed | RHSA-2026:47737 |
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:1782159791 | Fixed | RHSA-2026:29197 |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1782166952 | Fixed | RHSA-2026:29197 |
| Red Hat Enterprise Linux 10 | openssl-1:3.5.5-4.el10_2 | Fixed | RHSA-2026:25237 |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | openssl-0:1.0.1e-61.el6_10.1 | Fixed | RHSA-2026:66524 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | openssl-1:1.0.2k-26.el7_9.2 | Fixed | RHSA-2026:58563 |
| Red Hat Enterprise Linux 8 | compat-openssl10-1:1.0.2o-4.el8_10.3 | Fixed | RHSA-2026:36215 |
| Red Hat Enterprise Linux 8 | openssl-1:1.1.1k-16.el8_6 | Fixed | RHSA-2026:26275 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | openssl-1:1.1.1k-16.el8_6 | Fixed | RHSA-2026:26275 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | compat-openssl10-1:1.0.2o-4.el8_8.1 | Fixed | RHSA-2026:36217 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | openssl-1:1.1.1k-16.el8_6 | Fixed | RHSA-2026:26275 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | compat-openssl10-1:1.0.2o-4.el8_8.1 | Fixed | RHSA-2026:36217 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | openssl-1:1.1.1k-16.el8_6 | Fixed | RHSA-2026:26275 |
| Red Hat Enterprise Linux 9 | compat-openssl11-1:1.1.1k-5.el9_8.4 | Fixed | RHSA-2026:44438 |
| Red Hat Enterprise Linux 9 | openssl-1:3.5.5-4.el9_8 | Fixed | RHSA-2026:25239 |
| Red Hat Enterprise Linux 9 | openssl-1:3.5.5-4.el9_8 | Fixed | RHSA-2026:25239 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | compat-openssl11-1:1.1.1k-4.el9_2.2 | Fixed | RHSA-2026:39012 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | compat-openssl11-1:1.1.1k-5.el9_4.3 | Fixed | RHSA-2026:39009 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | compat-openssl11-1:1.1.1k-5.el9_6.3 | Fixed | RHSA-2026:35869 |
| Red Hat Hardened Images | chunkah-main-0.6.0-3.hum1 | Fixed | RHSA-2026:42825 |
| Red Hat Hardened Images | openssl-main-3.5.8-0.1.hum1 | Fixed | RHSA-2026:59641 |
| Red Hat Hardened Images | openssl3-main-3.5.8-0.1.hum1 | Fixed | RHSA-2026:59635 |
| Red Hat Hardened Images | python-cryptography-main-50.0.0-1.hum1 | Fixed | RHSA-2026:55543 |
| Red Hat Hardened Images | ruby3-3-main-3.3.10-23.6.hum1 | Fixed | RHSA-2026:62562 |
| Red Hat Hardened Images | ruby3-4-main-3.4.10-31.7.hum1 | Fixed | RHSA-2026:62790 |
| Red Hat Hardened Images | ruby4-0-main-4.0.6-37.3.hum1 | Fixed | RHSA-2026:62563 |
| Red Hat Hardened Images | rust-bootupd-main-0.3.2-1.hum1 | Fixed | RHSA-2026:67551 |
| Red Hat Insights proxy 1.5 | insights-proxy/insights-proxy-container-rhel9:1782890503 | Fixed | RHSA-2026:34102 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202608241157-0 | Fixed | RHSA-2026:59831 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-tp-rhel9:1787241211 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1781525684 | Fixed | RHSA-2026:26319 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9:1781525671 | Fixed | RHSA-2026:26319 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1781525693 | Fixed | RHSA-2026:26319 |
| Red Hat Update Infrastructure 5 | rhui5/installer-tp-rhel9:1787135742 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1781525739 | Fixed | RHSA-2026:26319 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| multicluster engine for Kubernetes 2.8 | multicluster-engine/console-mce-rhel9:1785078604 | Fixed | RHSA-2026:47735 |
| Multicluster Engine for Kubernetes | multicluster-engine/hive-rhel9 | Under investigation | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/hypershift-rhel9-operator | Under investigation | n/a |
| Red Hat Enterprise Linux 10 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 10 | shim-unsigned-aarch64 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | shim-unsigned-x64 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 7 | shim-signed | Not affected | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mingw-openssl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 8 | shim-unsigned-x64 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim-unsigned-aarch64 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim-unsigned-x64 | Not affected | n/a |
| Red Hat Hardened Images | netavark | Not affected | n/a |
| Red Hat Hardened Images | openshell | Not affected | n/a |
| Red Hat Hardened Images | rust | Not affected | n/a |
| Red Hat Hardened Images | rust-podman-sequoia | Not affected | n/a |
| Red Hat Hardened Images | unbound | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-openssl | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-openssl-win6-x86_64.zip | Not affected | n/a |
| Red Hat JBoss Web Server 6 | jws-optional-native-components-win6-x86_64.zip | Not affected | n/a |
| Red Hat JBoss Web Server 7 | jws-optional-native-components-win6-x86_64.zip | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This High severity heap use-after-free flaw in OpenSSL's PKCS7_verify() function can be triggered by processing a specially crafted PKCS#7 or S/MIME signed message. This could lead to application crashes, memory corruption, or potentially remote code execution, impacting services that handle such messages. The vulnerability specifically affects applications utilizing OpenSSL PKCS#7 APIs, while those using CMS APIs are not impacted.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (31)
- https://access.redhat.com/errata/RHSA-2026:25237
- https://access.redhat.com/errata/RHSA-2026:25239
- https://access.redhat.com/errata/RHSA-2026:26275
- https://access.redhat.com/errata/RHSA-2026:26319
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/errata/RHSA-2026:34102
- https://access.redhat.com/errata/RHSA-2026:35869
- https://access.redhat.com/errata/RHSA-2026:36215
- https://access.redhat.com/errata/RHSA-2026:36217
- https://access.redhat.com/errata/RHSA-2026:39009
- https://access.redhat.com/errata/RHSA-2026:39012
- https://access.redhat.com/errata/RHSA-2026:39981
- https://access.redhat.com/errata/RHSA-2026:44438
- https://access.redhat.com/errata/RHSA-2026:47735
- https://access.redhat.com/errata/RHSA-2026:47737
- https://access.redhat.com/errata/RHSA-2026:58563
- https://access.redhat.com/errata/RHSA-2026:58981
- https://access.redhat.com/errata/RHSA-2026:59831
- https://access.redhat.com/errata/RHSA-2026:66524
- https://access.redhat.com/security/cve/CVE-2026-45447 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2481898 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35491 Advisory
- https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c patch
- https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8 patch
- https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54 patch
- https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c patch
- https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-45447
- https://openssl-library.org/news/secadv/20260609.txt vendor-advisoryVendor Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json
- https://www.cve.org/CVERecord?id=CVE-2026-45447
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data