CVE-2026-84783 OpenSSL X.509 证书缓存释放后使用漏洞
影响远程未认证攻击者可触发进程崩溃,造成拒绝服务
OpenSSL 在首次使用同一 X.509 证书时会缓存其扩展解码值。在 OpenSSL 4.0 中该缓存分两阶段构建,多线程并发构建同一证书缓存时,后获得写锁的线程会释放前一线程已安装的扩展数据,而其他线程仍在使用,形成释放后使用(UAF)。
影响范围
据描述影响 OpenSSL 4.0 版本;其他版本是否受影响暂无公开信息,具体受影响版本范围建议以官方公告为准。
漏洞详情
漏洞类型为 CWE-416 释放后使用。成因是缓存构建时先持读锁计算扩展值、再持写锁安装结果,读锁不排斥其他读者,导致多线程可同时为同一证书计算缓存,写锁安装时释放他人数据。利用方式为远程未认证对端在首次构建到同一受信任 CA 的证书链时并发触发,造成 UAF 读取并崩溃进程。
利用条件与风险
利用前提是多线程 TLS 客户端,或请求客户端证书的多线程 TLS 服务端,且多个连接同时首次构建到同一受信任 CA 的证书链;远程未认证即可触发,实战风险为拒绝服务。
修复建议
官方修复方案与临时缓解措施暂无公开信息,建议关注 OpenSSL 官方安全公告并升级至修复版本;临时可考虑减少并发首次证书链构建或限制客户端证书请求。
Issue summary: The first concurrent use of the same X.509 certificate by
several threads may cause its cached extension data to be freed while
another thread is still using it.
Impact summary: A remote, unauthenticated peer could crash a multi-threaded
TLS client, or a multi-threaded TLS server that requests client
certificates, if the first certificate chains built to the same trusted CA
certificate are built by several connections at the same time. This is a
use-after-free read, which is likely to crash the process, resulting in a
Denial of Service.
CWE: CWE-416: Use After Free
Description: OpenSSL caches the decoded values of a certificate’s X.509v3
extensions inside the X509 object the first time they are needed. In
OpenSSL 4.0 this cache is built in two phases: the extension values are
computed while holding a read lock on the certificate, and the results are
then installed into the certificate under a write lock. Because a read lock
does not exclude other readers, several threads can compute the cache for
the same certificate at the same time. Each thread that subsequently
acquires the write lock installs its own results and frees the values
installed by the thread before it, even though that earlier thread has
already marked the cache as complete and may have returned pointers into it
to its caller. A caller still using those pointers then reads freed memory.
Any certificate shared between threads is exposed the first time its
extensions are decoded. In TLS the certificates at risk are the trusted CA
certificates supplied for chain verification, by whatever means, since these
are shared by every connection and their extensions are decoded and cached
the first time a chain is built to them. Certificates sent by the peer are
decoded separately for each connection and are not shared, so they are not
affected. In a TLS client verifying server certificates, or a TLS server
that requests and verifies client certificates, the use-after-free could
only occur if the first chains built to the same trusted CA are built by
several connections at the same time.
FIPS impact: no
The FIPS module is not affected as X.509 certificate handling is outside
of the OpenSSL FIPS module boundary.
OpenSSL 4.0 is vulnerable to this issue.
OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.
OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.
This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and
independently in a public report on 31 August 2026 by aydinmercan.
The fix has been developed by Bob Beck.
— cut (non-publishing metadata for internal use) —
Reported by: Tim Becker (Xint.io), aydinmercan
Fixed by: Bob Beck