Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-45447

46
FAUCET Score

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

First published: Jun 9, 2026Last modified: Jun 10, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.2, < 1.0.2zqCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.1.1, < 1.1.1zhCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.0.21CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.4.0, < 3.4.6CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.5.0, < 3.5.7CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
5.24%
Probability of exploitation in next 30 days
EPSS Percentile
91.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0524 is in the 85th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 edk2 20240524git3e722403cd16-17 on Azure Linux 3.0Fixed in: 20240524git3e722403cd16-18
microsoftpatch availablevia msrc
Product: azl3 openssl 3.3.7-3 on Azure Linux 3.0Fixed in: 3.3.7-4
microsoftpatch availablevia msrc
Product: 21450-17084Fixed in: 20240524git3e722403cd16-18
ubuntupatch availablevia ubuntu_usn
Product: openssl (focal)Fixed in: 1.1.1f-1ubuntu2.24+esm4
ubuntupatch availablevia ubuntu_usn
Product: openssl (trusty)Fixed in: 1.0.1f-1ubuntu2.27+esm14
ubuntupatch availablevia ubuntu_usn
Product: openssl (xenial)Fixed in: 1.0.2g-1ubuntu4.20+esm16
ubuntupatch availablevia ubuntu_usn
Product: openssl (jammy)Fixed in: 3.0.2-0ubuntu1.25
ubuntupatch availablevia ubuntu_usn
Product: openssl (noble)Fixed in: 3.0.13-0ubuntu3.11
ubuntupatch availablevia ubuntu_usn
Product: openssl (questing)Fixed in: 3.5.3-1ubuntu3.4
ubuntupatch availablevia ubuntu_usn
Product: openssl (resolute)Fixed in: 3.5.5-1ubuntu3.2
ubuntupatch availablevia ubuntu_usn
Product: openssl (bionic)Fixed in: 1.1.1-1ubuntu2.1~18.04.23+esm9
ubuntupatch availablevia ubuntu_usn
Product: openssl1.0 (bionic)Fixed in: 1.0.2n-1ubuntu5.13+esm5

Vendor Advisories (3)

ubuntuUSN-8414-2

OpenSSL vulnerabilities

Jun 9, 2026
ubuntuUSN-8414-1

OpenSSL vulnerabilities

Jun 9, 2026
microsoft2026-Jun/CVE-2026-45447Important

Heap Use-After-Free in the PKCS7_verify() Function

Jun 9, 2026

References

access.redhat.com / errata/RHSA-2026:25237
access.redhat.com / errata/RHSA-2026:25239
access.redhat.com / errata/RHSA-2026:26275
access.redhat.com / errata/RHSA-2026:26319
access.redhat.com / errata/RHSA-2026:29197
access.redhat.com / errata/RHSA-2026:34102
access.redhat.com / errata/RHSA-2026:35869
access.redhat.com / errata/RHSA-2026:36215
access.redhat.com / errata/RHSA-2026:36217
access.redhat.com / errata/RHSA-2026:39009
access.redhat.com / errata/RHSA-2026:39012
access.redhat.com / errata/RHSA-2026:39981
access.redhat.com / errata/RHSA-2026:44438
access.redhat.com / security/cve/CVE-2026-45447
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-45447.json
github.com / openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c
Patch
github.com / openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8
Patch
github.com / openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54
Patch
github.com / openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c
Patch
github.com / openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e
Patch
openssl-library.org / news/secadv/20260609.txt
Vendor Advisory