CVE-2026-75805 OpenSSL CMP 客户端空指针解引用漏洞
影响攻击者可导致 CMP 客户端崩溃,造成拒绝服务
OpenSSL 的 CMP 客户端在使用 PKCS#10 CSR 请求证书吊销时,若服务器返回特制的证书名称,客户端会解引用空指针并异常终止。该缺陷属于空指针解引用(CWE-476),仅导致客户端崩溃,不涉及代码执行或数据泄露。
影响范围
受影响组件为 OpenSSL 的 CMP 客户端功能,涉及命令行 openssl cmp -cmd rr -csr 及 API OSSL_CMP_exec_RR_ses() 配合 OSSL_CMP_CTX_set1_p10CSR() 的使用场景;具体受影响版本范围暂无公开信息。
漏洞详情
当客户端以 PKCS#10 CSR 方式发起证书吊销请求时,CSR 中不包含证书的颁发者名称和序列号,因此客户端不会发送这些信息。服务器在响应中可选地返回其吊销的证书名称,客户端会将该名称与自身发送的内容进行比对。由于客户端未发送颁发者名称和序列号,比对时缺少有效数据,遇到特制名称即从空指针读取,导致崩溃。
利用条件与风险
利用前提是客户端使用 CSR 方式发起吊销请求,且连接的服务器(或中间人)返回特制响应。实战中可造成客户端拒绝服务,CVSS 5.3 属中危,通常需要攻击者控制或冒充 CMP 服务器。
修复建议
建议关注 OpenSSL 官方针对 CVE-2026-75805 发布的修复版本并尽快升级;临时缓解措施包括避免使用 CSR 方式发起吊销请求,或对 CMP 服务器响应来源进行严格校验,具体方案以官方公告为准。
Issue summary: A CMP client that requests certificate revocation on the basis
of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when
processing a crafted revocation response.
Impact summary: The NULL pointer dereference happens on a read which
leads to a crash and a Denial of Service for the affected client application.
CWE: CWE-476: NULL-pointer dereference
Description: A CMP client revoking a certificate has to tell the server which
certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the
certificate itself or its issuer name and serial number. This is
‘openssl cmp -cmd rr -csr ‘ on the command line, or
OSSL_CMP_exec_RR_ses() with the certificate supplied via
OSSL_CMP_CTX_set1_p10CSR() through the API.
A CSR does not contain the issuer name and serial number of the certificate,
so the client does not send them. A server may optionally name the
certificate it revoked in its response, and the client then compares that
name against what it sent. Having sent neither an issuer name nor a serial
number, it has nothing to compare against, and a server returning a specially
crafted name causes the client to read from a NULL pointer and crash.
The revocation response is checked for valid message protection before
the affected code is reached, so an attacker must be a malicious or
compromised CMP server, or a man-in-the-middle in possession of the
secret used for message protection. Clients that identify the certificate
to be revoked by a certificate or by issuer and serial number rather
than by a PKCS#10 CSR are not affected.
FIPS impact: no
No FIPS modules are affected by this issue, as the CMP protocol
implementation is outside the OpenSSL FIPS module boundary.