openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch

cve CVE-2026-72897 3 sources, 3 claims · Watch

Red Hat writes:
openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectsopenssl/openssl
NVD says “OpenSSL · OpenSSL”
made_byopenssl
NVD says “OpenSSL”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
GitHub advisories7.5
receipt
Source
GitHub advisories
Its words
7.5
Read by
field:cvss.score
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-72897",
  "cvss": {
    "score": 7.5,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.5,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-787",
      "name": "Out-of-bounds Write"
    }
  ],
  "description": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
  "epss": {
    "percentage": 0.00266,
    "percentile": 0.16682
  },
  "ghsa_id": "GHSA-x8gv-f6w5-h79g",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-x8gv-f6w5-h79g",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-x8gv-f6w5-h79g"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-72897"
    }
  ],
  "nvd_published_at": "2026-09-29T16:17:09Z",
  "published_at": "2026-09-29T18:31:44Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-72897",
    "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922",
    "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e",
    "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61",
    "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814",
    "https://openssl-library.org/news/secadv/20260929.txt",
    "https://github.com/advisories/GHSA-x8gv-f6w5-h79g"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different...",
  "type": "unreviewed",
  "updated_at": "2026-09-29T18:31:49Z",
  "url": "https://api.github.com/advisories/GHSA-x8gv-f6w5-h79g",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Cvss
cvss
conflict
NVD7.5
receipt
Source
NVD
Its words
7.5
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-10-02 12:00 UTC7.5
2026-09-29 17:49 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "OpenSSL",
            "vendor": "OpenSSL",
            "versions": [
              {
                "lessThan": "4.0.3",
                "status": "affected",
                "version": "4.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.6.5",
                "status": "affected",
                "version": "3.6.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.5.9",
                "status": "affected",
                "version": "3.5.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.4.8",
                "status": "affected",
                "version": "3.4.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "openssl-security@openssl.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."
      }
    ],
    "id": "CVE-2026-72897",
    "lastModified": "2026-09-29T21:27:41.130",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-72897",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-29T17:16:29.979390Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-29T16:17:09.903",
    "references": [
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://openssl-library.org/news/secadv/20260929.txt"
      }
    ],
    "sourceIdentifier": "openssl-security@openssl.org",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "openssl-security@openssl.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
conflict
Red Hat5.9
receipt
Source
Red Hat
Its words
5.9
Read by
field:cvss3_score
Said since
2026-10-02 12:01 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-72897",
  "CWE": "CWE-787",
  "advisories": [
    "RHSA-2026:74162",
    "RHSA-2026:74166"
  ],
  "affected_packages": [
    "openssl-main-3.5.9-0.1.hum1",
    "openssl3-main-3.5.9-0.1.hum1"
  ],
  "bugzilla": "2543259",
  "bugzilla_description": "openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch",
  "cvss3_score": "5.9",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-29T15:32:18Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-72897.json",
  "severity": "moderate"
}
—
Cwe
cwe
GitHub advisoriesCWE-787
receipt
Source
GitHub advisories
Its words
CWE-787
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-72897",
  "cvss": {
    "score": 7.5,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.5,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-787",
      "name": "Out-of-bounds Write"
    }
  ],
  "description": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
  "epss": {
    "percentage": 0.00266,
    "percentile": 0.16682
  },
  "ghsa_id": "GHSA-x8gv-f6w5-h79g",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-x8gv-f6w5-h79g",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-x8gv-f6w5-h79g"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-72897"
    }
  ],
  "nvd_published_at": "2026-09-29T16:17:09Z",
  "published_at": "2026-09-29T18:31:44Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-72897",
    "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922",
    "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e",
    "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61",
    "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814",
    "https://openssl-library.org/news/secadv/20260929.txt",
    "https://github.com/advisories/GHSA-x8gv-f6w5-h79g"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different...",
  "type": "unreviewed",
  "updated_at": "2026-09-29T18:31:49Z",
  "url": "https://api.github.com/advisories/GHSA-x8gv-f6w5-h79g",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Cwe
cwe
Red HatCWE-787
receipt
Source
Red Hat
Its words
CWE-787
Read by
field:CWE
Said since
2026-10-02 12:01 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-72897",
  "CWE": "CWE-787",
  "advisories": [
    "RHSA-2026:74162",
    "RHSA-2026:74166"
  ],
  "affected_packages": [
    "openssl-main-3.5.9-0.1.hum1",
    "openssl3-main-3.5.9-0.1.hum1"
  ],
  "bugzilla": "2543259",
  "bugzilla_description": "openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch",
  "cvss3_score": "5.9",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-29T15:32:18Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-72897.json",
  "severity": "moderate"
}
—
Packages
packages
Red Hatopenssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1
receipt
Source
Red Hat
Its words
openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1
Read by
field:affected_packages[]
Said since
2026-10-02 12:01 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-72897",
  "CWE": "CWE-787",
  "advisories": [
    "RHSA-2026:74162",
    "RHSA-2026:74166"
  ],
  "affected_packages": [
    "openssl-main-3.5.9-0.1.hum1",
    "openssl3-main-3.5.9-0.1.hum1"
  ],
  "bugzilla": "2543259",
  "bugzilla_description": "openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch",
  "cvss3_score": "5.9",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-29T15:32:18Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-72897.json",
  "severity": "moderate"
}
—
Product
product
NVDOpenSSL
receipt
Source
NVD
Its words
OpenSSL
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "OpenSSL",
            "vendor": "OpenSSL",
            "versions": [
              {
                "lessThan": "4.0.3",
                "status": "affected",
                "version": "4.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.6.5",
                "status": "affected",
                "version": "3.6.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.5.9",
                "status": "affected",
                "version": "3.5.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.4.8",
                "status": "affected",
                "version": "3.4.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "openssl-security@openssl.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."
      }
    ],
    "id": "CVE-2026-72897",
    "lastModified": "2026-09-29T21:27:41.130",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-72897",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-29T17:16:29.979390Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-29T16:17:09.903",
    "references": [
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://openssl-library.org/news/secadv/20260929.txt"
      }
    ],
    "sourceIdentifier": "openssl-security@openssl.org",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "openssl-security@openssl.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
GitHub advisorieshigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Its words
high
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-72897",
  "cvss": {
    "score": 7.5,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.5,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-787",
      "name": "Out-of-bounds Write"
    }
  ],
  "description": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
  "epss": {
    "percentage": 0.00266,
    "percentile": 0.16682
  },
  "ghsa_id": "GHSA-x8gv-f6w5-h79g",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-x8gv-f6w5-h79g",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-x8gv-f6w5-h79g"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-72897"
    }
  ],
  "nvd_published_at": "2026-09-29T16:17:09Z",
  "published_at": "2026-09-29T18:31:44Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-72897",
    "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922",
    "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e",
    "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61",
    "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814",
    "https://openssl-library.org/news/secadv/20260929.txt",
    "https://github.com/advisories/GHSA-x8gv-f6w5-h79g"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different...",
  "type": "unreviewed",
  "updated_at": "2026-09-29T18:31:49Z",
  "url": "https://api.github.com/advisories/GHSA-x8gv-f6w5-h79g",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Severity
severity
conflict
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-10-02 12:01 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-72897",
  "CWE": "CWE-787",
  "advisories": [
    "RHSA-2026:74162",
    "RHSA-2026:74166"
  ],
  "affected_packages": [
    "openssl-main-3.5.9-0.1.hum1",
    "openssl3-main-3.5.9-0.1.hum1"
  ],
  "bugzilla": "2543259",
  "bugzilla_description": "openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch",
  "cvss3_score": "5.9",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-29T15:32:18Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-72897.json",
  "severity": "moderate"
}
medium
Status
status
NVDAwaiting Analysis
receipt
Source
NVD
Its words
Awaiting Analysis
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-10-02 12:00 UTCAwaiting Analysis
2026-09-29 17:49 UTCReceived
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "OpenSSL",
            "vendor": "OpenSSL",
            "versions": [
              {
                "lessThan": "4.0.3",
                "status": "affected",
                "version": "4.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.6.5",
                "status": "affected",
                "version": "3.6.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.5.9",
                "status": "affected",
                "version": "3.5.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.4.8",
                "status": "affected",
                "version": "3.4.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "openssl-security@openssl.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."
      }
    ],
    "id": "CVE-2026-72897",
    "lastModified": "2026-09-29T21:27:41.130",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-72897",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-29T17:16:29.979390Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-29T16:17:09.903",
    "references": [
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://openssl-library.org/news/secadv/20260929.txt"
      }
    ],
    "sourceIdentifier": "openssl-security@openssl.org",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "openssl-security@openssl.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDOpenSSL
receipt
Source
NVD
Its words
OpenSSL
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "OpenSSL",
            "vendor": "OpenSSL",
            "versions": [
              {
                "lessThan": "4.0.3",
                "status": "affected",
                "version": "4.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.6.5",
                "status": "affected",
                "version": "3.6.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.5.9",
                "status": "affected",
                "version": "3.5.0",
                "versionType": "semver"
              },
              {
                "lessThan": "3.4.8",
                "status": "affected",
                "version": "3.4.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "openssl-security@openssl.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."
      }
    ],
    "id": "CVE-2026-72897",
    "lastModified": "2026-09-29T21:27:41.130",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-72897",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-29T17:16:29.979390Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-29T16:17:09.903",
    "references": [
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814"
      },
      {
        "source": "openssl-security@openssl.org",
        "url": "https://openssl-library.org/news/secadv/20260929.txt"
      }
    ],
    "sourceIdentifier": "openssl-security@openssl.org",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "openssl-security@openssl.org",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch
zetlyn/cve-redhat · 2026-09-29
cvss 5.9 cwe CWE-787 packages openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1 severity moderate source
Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.
zetlyn/cve-nvd · 2026-09-29
cvss 7.5 product OpenSSL status Awaiting Analysis vendor OpenSSL source
Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different...
zetlyn/cve-ghsa · 2026-09-29
cvss 7.5 cwe CWE-787 severity high source