天下漏洞,尽知其名
HIGH

CVE-2026-72897 OpenSSL SSL_set_SSL_CTX 越界读写漏洞

影响远程对端可触发越界读写,导致服务端拒绝服务

AI 研判

OpenSSL 在处理 TLS 握手过程中调用 SSL_set_SSL_CTX() 切换连接上下文时,未刷新连接创建时记录的证书槽位数量,导致内部数组越界访问。该问题被分配为 CVE-2026-72897,评级 HIGH(CVSS 7.5),属于 CWE-787 越界写。

影响范围

OpenSSL

仅影响在握手过程中调用 SSL_set_SSL_CTX() 的 TLS 服务端应用,典型场景为基于 servername 回调切换虚拟主机;未调用该接口的应用不受影响。具体受影响版本范围暂无公开信息。

漏洞详情

TLS 连接创建时会依据其 SSL_CTX 已知的 provider 签名算法数量确定内部证书有效性标志数组的大小。若应用在握手途中通过 SSL_set_SSL_CTX() 切换到已知更多签名算法的上下文,而记录的槽位数量未同步更新,后续访问该数组即会越界。攻击者可借此造成小范围越界读,特定情况下还可触发固定值的越界写。

利用条件与风险

利用前提是服务端应用在握手期间调用 SSL_set_SSL_CTX() 切换上下文,且替换后的上下文知晓更多 provider 签名算法;远程对端可主动触发,实战中主要导致服务端拒绝服务。

修复建议

建议关注 OpenSSL 官方针对 CVE-2026-72897 发布的修复版本并及时升级;临时缓解措施为避免在握手过程中使用 SSL_set_SSL_CTX() 切换上下文,或确保替换上下文与原始上下文具有相同的签名算法配置。具体修复版本暂无公开信息。

原始情报

Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a
connection to a different SSL_CTX part way through a handshake may access
memory beyond the end of an internal array if the replacement context knows
about more provider signature algorithms than the context the connection was
created from. Applications which never call SSL_set_SSL_CTX() are not
affected.

Impact summary: A remote peer may be able to cause a small out-of-bounds
read, and in some circumstances a fixed-value out-of-bounds write, on the
server heap. This may lead to a Denial of Service.

CWE: CWE-787: Out-of-bounds Write

Description: A TLS connection records how many certificate slots it has
when it is created, taken from the SSL_CTX that created it: the built-in
certificate types plus one slot for each provider TLS-SIGALG entry that
context was aware of. That count sizes an internal array of per-slot
certificate validity flags.

An application may replace a connection’s SSL_CTX part way through the
handshake by calling SSL_set_SSL_CTX(), most commonly from a servername
callback in order to serve a different virtual host. Doing so did not
refresh the recorded count. A provider signature algorithm’s slot index is
its position in the list of whichever context resolves it, so if the
replacement context is aware of more of them than the original, an
algorithm offered by the peer can resolve to an index beyond the end of the
array. Processing the peer’s signature algorithms then reads one four byte
word past the end for each such algorithm and, where the word read is zero,
writes a fixed value over it. A peer offering many of them can corrupt heap
metadata and abort the process.

Only provider signature algorithms which occupy one of the excess slots,
and which the server also has configured, have this effect. Codepoints the
replacement context does not recognise are discarded without being resolved
to a slot, and provider signature algorithms are usable only from TLS 1.3.

The two contexts must therefore be aware of different numbers of provider
signature algorithms, which requires separate library contexts, a provider
loaded between the two being created, or providers which differ in what
they advertise – in 4.0, for example, the default provider advertises SM2
where the FIPS provider does not. A deployment meeting the condition is
also unable to negotiate the affected algorithms with legitimate clients,
since the same stale count hides the corresponding certificates, so the
misconfiguration is likely to be noticed. For that reason, and because the
configuration is not the default, this issue has been assessed as Low
severity.

FIPS impact: no
No FIPS modules are affected by this issue as the affected code is outside
the OpenSSL FIPS module boundary.