CVE-2026-45447:OpenSSL PKCS7_verify() 函数中的堆释放后使用漏洞

Lobsters Hottest 新闻

摘要

OpenSSL PKCS7_verify() 函数中发现了一个堆释放后使用漏洞,可能允许攻击者利用内存破坏。

<p><a href="https://lobste.rs/s/yg1xb2/cve_2026_45447_heap_use_after_free_openssl">评论</a></p>
查看原文
查看缓存全文

缓存时间: 2026/06/10 05:45

# 漏洞 | OpenSSL 库 来源:https://openssl-library.org/news/vulnerabilities/index.html 如果您认为在 OpenSSL 中发现了安全漏洞,请通过此链接报告给我们 (https://openssl-library.org/community/#reporting-security-bugssecurityreports) 显示仅修复于以下版本的漏洞:OpenSSL4.0 (https://openssl-library.org/news/vulnerabilities-4.0)、3.6 (https://openssl-library.org/news/vulnerabilities-3.6)、3.5 (https://openssl-library.org/news/vulnerabilities-3.5)、3.4 (https://openssl-library.org/news/vulnerabilities-3.4)、3.3 (https://openssl-library.org/news/vulnerabilities-3.3)、3.2 (https://openssl-library.org/news/vulnerabilities-3.2)、3.1 (https://openssl-library.org/news/vulnerabilities-3.1)、3.0 (https://openssl-library.org/news/vulnerabilities-3.0)、1.1.1 (https://openssl-library.org/news/vulnerabilities-1.1.1)、1.1.0 (https://openssl-library.org/news/vulnerabilities-1.1.0)、1.0.2 (https://openssl-library.org/news/vulnerabilities-1.0.2)、1.0.1 (https://openssl-library.org/news/vulnerabilities-1.0.1)、1.0.0 (https://openssl-library.org/news/vulnerabilities-1.0.0)、0.9.8 (https://openssl-library.org/news/vulnerabilities-0.9.8)、0.9.7 (https://openssl-library.org/news/vulnerabilities-0.9.7)、0.9.6 (https://openssl-library.org/news/vulnerabilities-0.9.6) 注意:所有 1.1.1 之前的 OpenSSL 版本已停止支持,不再接收更新。OpenSSL Software Services 为高级支持客户提供 1.0.2 的扩展支持。 跳转到年份:2026 (https://openssl-library.org/news/vulnerabilities/index.html#2026)、2025 (https://openssl-library.org/news/vulnerabilities/index.html#2025)、2024 (https://openssl-library.org/news/vulnerabilities/index.html#2024)、2023 (https://openssl-library.org/news/vulnerabilities/index.html#2023)、2022 (https://openssl-library.org/news/vulnerabilities/index.html#2022)、2021 (https://openssl-library.org/news/vulnerabilities/index.html#2021)、2020 (https://openssl-library.org/news/vulnerabilities/index.html#2020)、2019 (https://openssl-library.org/news/vulnerabilities/index.html#2019)、2018 (https://openssl-library.org/news/vulnerabilities/index.html#2018)、2017 (https://openssl-library.org/news/vulnerabilities/index.html#2017)、2016 (https://openssl-library.org/news/vulnerabilities/index.html#2016)、2015 (https://openssl-library.org/news/vulnerabilities/index.html#2015)、2014 (https://openssl-library.org/news/vulnerabilities/index.html#2014)、2013 (https://openssl-library.org/news/vulnerabilities/index.html#2013)、2012 (https://openssl-library.org/news/vulnerabilities/index.html#2012)、2011 (https://openssl-library.org/news/vulnerabilities/index.html#2011)、2010 (https://openssl-library.org/news/vulnerabilities/index.html#2010)、2009 (https://openssl-library.org/news/vulnerabilities/index.html#2009)、2008 (https://openssl-library.org/news/vulnerabilities/index.html#2008)、2007 (https://openssl-library.org/news/vulnerabilities/index.html#2007)、2006 (https://openssl-library.org/news/vulnerabilities/index.html#2006)、2005 (https://openssl-library.org/news/vulnerabilities/index.html#2005)、2004 (https://openssl-library.org/news/vulnerabilities/index.html#2004)、2003 (https://openssl-library.org/news/vulnerabilities/index.html#2003)、2002 (https://openssl-library.org/news/vulnerabilities/index.html#2002) ## 2026 ### CVE-2026-34180 (https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-34180)问题摘要:解析一个精心构造的 DER 编码的 ASN.1 结构,其中包含一个原始元素,其内容长度超过 2 GB,可能导致在 64 位 Unix 及类 Unix 平台上发生堆缓冲区越界读取。 影响摘要:堆缓冲区越界读取可能导致应用程序崩溃(拒绝服务),或将输入缓冲区末尾之后的内存内容加载到解码后的 ASN.1 对象中。更常见的情况是,此类 ASN.1 元素会被截断。 OpenSSL ASN.1 解码器中的整数截断问题导致当 ASN.1 原始元素的内容长度超过 2 GB 时处理错误。在最坏情况下,截断后的长度会被视为扫描二进制内容以查找终止零字节的请求,可能导致 OpenSSL 读取少于或超出分配缓冲区末尾的数据。 传递攻击者提供的数据给 d2i_X509()、d2i_PKCS7() 或任何其他 d2i_* 解码函数的应用程序都会受到影响。OpenSSL 自己的命令行工具不受影响,因为通过 BIO 层读取的数据在到达受影响代码之前会被检查。此问题仅影响 64 位 Unix 及类 Unix 平台;32 位平台和 64 位 Windows 不受影响。 4.0、3.6、3.5、3.4 和 3.0 中的 FIPS 模块不受此问题影响,因为受影响的代码位于 OpenSSL FIPS 模块边界之外。 ### CVE-2026-34181 (https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-34181)问题摘要:PKCS#12 文件处理未能对使用基于密码的消息认证码 1(PBMAC1)完整性机制的文件执行充分的输入验证,导致证书和私钥伪造。 影响摘要:攻击者冒充用户,有 1/256 的概率导致读取 PKCS#12 文件的服务接受伪造的证书和私钥。 如果接受 PKCS#12 文件的服务使用密码进行文件身份验证,攻击者可以创建未加密的 PKCS#12 文件,使用 PBMAC1 认证,并指定仅一个字节的 HMAC 密钥,从而以 1/256 的概率构造一个被接受的文件。这将导致服务接受攻击者控制的证书和私钥。 FIPS 模块不受此问题影响,因为受影响的代码位于 OpenSSL FIPS 模块边界之外。 ### CVE-2026-34182 (https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-34182)问题摘要:加密消息服务(CMS)处理未能对 AuthEnvelopedData 容器中的密码和标签长度字段执行充分的输入验证,导致各种潜在危害。 影响摘要:利用这些漏洞的攻击者可能实现对 CMS 收件人的密钥等效功能,和/或绕过给定消息的完整性验证。 在一种使用场景中,攻击者可能发送包含 AuthEnvelopedData 的 CMS 消息,其中密码指定为非 AEAD 密码。OpenSSL 错误地允许此选择,并尝试解密和验证消息。 中间人攻击者捕获一个发送给受害者的合法 AES-GCM AuthEnvelopedData 后,可以重新发送它,并保持 recipientInfos 设置逐字节不变,因此受害者的私钥仍然可以解开真实的 CEK(内容加密密钥),但内部 OID 被重写为 AES-256-OFB(输出反馈模式,一种未认证的密钥流模式),并使用攻击者选择的 IV 和密文。受害者使用真实的 CEK 初始化 AES-256-OFB,从不检查 MAC 字段,而 CMS_decrypt() 返回成功。 如果受攻击的应用程序向攻击者响应任何指示解密成功或失败的信号,攻击者可以利用此信号作为预言机,为消息中选定收件人使用的 CEK 获得密钥等效功能。 在另一种使用场景中,攻击者可以将给定 AuthEnvelopedData 容器中选定的 AEAD 密码的标签长度减少为单个字节,从而允许攻击者暴力破解 CMS 解密,对于信任 CMS_decrypt() 拒绝修改内容的应用程序来说,这会导致完整性绕过。 FIPS 模块不受此问题影响。 ### CVE-2026-34183 (https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-34183)问题摘要:远程对等节点可以通过用包含 PATH_CHALLENGE 帧的数据包淹没 QUIC 服务器或客户端,从而耗尽堆内存。 影响摘要:恶意远程对等节点可能导致无限制的内存分配,进而导致作为 QUIC 客户端或服务器的应用程序异常终止和拒绝服务。 远程对等节点可以通过用 PATH_CHALLENGE 帧淹没本地 QUIC 栈来耗尽堆内存。本地 QUIC 栈为每个接收到的 PATH_CHALLENGE 分配一个 PATH_RESPONSE 帧。分配的 PATH_RESPONSE 帧仅当远程对等节点确认收到 PATH_RESPONSE 帧时才被释放,而恶意对等节点不会这样做。 4.0、3.6、3.5、3.4 和 3.0 中的 FIPS 模块不受此问题影响。QUIC 栈位于 OpenSSL FIPS 模块边界之外。 ### CVE-2026-35188 (https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-35188)严重程度 中等 发布时间 2026 年 6 月 9 日 标题 检查 OCSP 装订响应时的双重释放 发现者 Wang Kenaz(伊利诺伊大学)、Guido Vranken(Aisle Research)和 Aaron Grattafiori(Nvidia) 修复开发者 Daniel Kubec 受影响版本 - 从 4.0.0 起,早于 4.0.1 - 从 3.6.0 起,早于 3.6.3 参考资料 - CVE 记录 (https://www.cve.org/CVERecord?id=CVE-2026-35188) - OpenSSL 公告 (https://openssl-library.org/news/secadv/20260609.txt) - 4.0.1 git 提交 (https://github.com/openssl/security/commit/78d0154cffda03aaaac63a087cc523a6b35fa8fd) - 3.6.3 git 提交 (https://github.com/openssl/security/commit/131145d25659e8749a9ed1afb383484854cffb78) 问题摘要:恶意服务器可以利用 TLS OCSP 装订,通过 status_request 扩展传递精心构造的响应,在客户端的证书验证路径中触发双重释放。 影响摘要:成功利用允许攻击者通过双重释放破坏堆内存,可能导致拒绝服务,也可能导致攻击者控制的代码执行或其他未定义行为。 如果启用了 OCSP 装订,并且 TLS 客户端连接到恶意服务器,当检查装订响应时,精心构造的 OCSP 装订响应可以在 TLS 客户端中触发双重释放。 OCSP 装订默认未启用。通过双重释放实现可靠的代码执行在技术上很复杂,并且高度依赖于环境,但拒绝服务的影响很容易实现,因此评定为中等严重程度。 没有 FIPS 模块受此问题影响,因为受影响的代码位于 OpenSSL FIPS 模块边界之外。 ### CVE-2026-42764 (https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-42764)严重程度 中等 发布时间 2026 年 6 月 9 日 标题 QUIC 服务器初始数据包处理中的空指针解引用 发现者 Sunwoo Lee(KENTECH)、Hyuk Lim(KENTECH)和 Seunghyun Yoon(KENTECH) 修复开发者 Sunwoo Lee(KENTECH)、Hyuk Lim(KENTECH)和 Seunghyun Yoon(KENTECH) 受影响版本 - 从 4.0.0 起,早于 4.0.1 - 从 3.6.0 起,早于 3.6.3 - 从 3.5.0 起,早于 3.5.7 参考资料 - CVE 记录 (https://www.cve.org/CVERecord?id=CVE-2026-42764) - OpenSSL 公告 (https://openssl-library.org/news/secadv/20260609.txt) - 4.0.1 git 提交 (https://github.com/openssl/security/commit/bf29a458c1a231eca87e384c62b9c2553fa57a91) - 3.6.3 git 提交 (https://github.com/openssl/security/commit/a45a0aba8095682c88ff4fc4a784892b8c6f0677) - 3.5.7 git 提交 (https://github.com/openssl/security/commit/5e3ed291b8af0b03d5d3b9e56a1da69a187e9729) 问题摘要:接收到带有无效令牌的 QUIC 初始数据包可能触发 OpenSSL QUIC 服务器(禁用地址验证时)中的空指针解引用。 影响摘要:空指针解引用通常导致受影响的 QUIC 服务器进程异常终止和拒绝服务。 如果在 OpenSSL QUIC 服务器实现中禁用了地址验证,攻击者可以通过发送带有无效或过期令牌的初始数据包来使服务器崩溃。 默认情况下,OpenSSL QUIC 服务器实现中启用了客户端地址验证,因此默认配置不受此问题影响。但如果使用 SSL_new_listener() 调用时使用了 SSL_LISTENER_FLAG_NO_VALIDATE 标志,则会禁用地址验证,从而使易受攻击的代码可达。 4.0、3.6、3.5、3.4 和 3.0 中的 FIPS 模块不受此问题影响,因为受影响的代码位于 OpenSSL FIPS 模块边界之外。 ### CVE-2026-42765 (https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-42765)严重程度 低 发布时间 2026 年 6 月 9 日 标题 带有 OCSP 检查的证书验证中的空指针解引用 发现者 Joshua Rogers(Aisle Research) 修复开发者 Joshua Rogers(Aisle Research)和 Daniel Kubec 受影响版本 - 从 4.0.0 起,早于 4.0.1 - 从 3.6.0 起,早于 3.6.3 参考资料 - CVE 记录 (https://www.cve.org/CVERecord?id=CVE-2026-42765) - OpenSSL 公告 (https://openssl-library.org/news/secadv/20260609.txt) - 4.0.1 git 提交 (https://github.com/openssl/security/commit/14340b7fa1d444615486bc137014b064e64ec334) - 3.6.3 git 提交 (https://github.com/openssl/security/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97) 问题摘要:当启用部分链证书验证并同时对整个链进行 OCSP 响应检查时,如果验证的链没有自签名的可信锚点,将发生空指针解引用,导致进程崩溃。 影响摘要:空指针解引用可能触发崩溃,导致应用程序拒绝服务。 在对验证链中的证书执行 OCSP 响应检查时,代码总是尝试访问下一个证书作为颁发者。有一个针对自签名证书的检查。但是,当启用部分链验证且链没有自签名的可信锚点时,链中最后一个证书的颁发者将为 NULL。于是发生空指针解引用。 此问题仅影响在证书验证中同时启用 OCSP 验证(X509_V_FLAG_OCSP_RESP_CHECK_ALL)和部分链验证(X509_V_FLAG_PARTIAL_CHAIN)的应用程序。这两个标志默认都是禁用的。因此,我们将其评定为低严重程度。 没有 FIPS 模块受此问题影响,因为受影响的代码位于 OpenSSL FIPS 模块边界之外。 ### CVE-2026-42766 (https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-42766)严重程度 低 发布时间 2026 年 6 月 9 日 标题 基于密码的 CMS 解密中可能出现的空指针解引用 发现者 Mayank Jangid、Kushal Khemka、Hari Priandana、Bhabani Sankar Das 和 Qifan Zhang(Palo Alto Networks) 修复开发者 Igor Ustinov 受影响版本 - 从 4.0.0 起,早于 4.0.1 - 从 3.6.0 起,早于 3.6.3 - 从 3.5.0 起,早于 3.5.7 - 从 3.4.0 起,早于 3.4.6 - 从 3.0.0 起,早于 3.0.21 - 从 1.1.1 起,早于 1.1.1zh - 从 1.0.2 起,早于 1.0.2zq 参考资料 - CVE 记录 (https://www.cve.org/CVERecord?id=CVE-2026-42766) - OpenSSL 公告 (https://openssl-library.org/news/secadv/20260609.txt) - 4.0.1 git 提交 (https://github.com/openssl/security/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4) - 3.6.3 git 提交 (https://github.com/openssl/security/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8) - 3.5.7 git 提交 (https://github.com/openssl/security/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce) - 3.4.6 git 提交 (https://github.com/openssl/security/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4) - 3.0.21 git 提交 (https://github.com/openssl/security/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7) 问题摘要:一个精心构造的密码加密 CMS 消息可以在 CMS 解密过程中触发空指针解引用。 影响摘要:此空指针解引用导致应用程序崩溃和拒绝服务。 CMS PasswordRecipientInfo.keyDerivationAlgorithm 字段

相似文章

CVE-2026-45257:通过kTLS-RX在FreeBSD中的本地权限提升

Lobsters Hottest

FreeBSD中存在一个严重的本地权限提升漏洞(CVE-2026-45257),允许无特权用户将任意数据写入任何可读文件的页面缓存,绕过文件权限和标志,最终导致完全获取root权限。该漏洞影响FreeBSD 13.0及更高版本的默认安装,通过sendfile、KTLS和内核内AES-GCM解密的不安全组合实现。

I found a KVM guest-to-host heap corruption bug and someone else got there first

Lobsters Hottest

Blog post detailing the discovery of CVE-2026-53360, a heap out-of-bounds read/write in KVM's SEV-SNP Page State Change handler that lets a malicious guest corrupt host kernel memory. The author discusses the bug, his incorrect fix, the better fix from a duplicate reporter, and provides a CTF challenge.