CVE-2026-72897
Received Received - Intake

Out-of-bounds Write in OpenSSL TLS Server

Vulnerability report for CVE-2026-72897, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: OpenSSL Software Foundation

Description

Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openssl openssl *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a low-severity vulnerability in OpenSSL where a TLS server using SSL_set_SSL_CTX() to switch contexts mid-handshake may access memory beyond an internal array. The issue occurs if the new context supports more provider signature algorithms than the original. This can lead to a small out-of-bounds read or, in some cases, a fixed-value out-of-bounds write on the server heap, potentially causing a Denial of Service.

Detection Guidance

This vulnerability is specific to OpenSSL's TLS implementation and requires a misconfigured context switch via SSL_set_SSL_CTX(). Detection would involve checking OpenSSL versions and configurations where provider signature algorithms differ between contexts. No direct network detection commands are provided in the context.

Impact Analysis

A remote attacker could exploit this to cause a Denial of Service by triggering memory corruption on the server. This requires a specific misconfiguration where contexts with differing numbers of provider signature algorithms are used during a handshake. Normal deployments are unlikely affected as the issue requires non-default configurations.

Mitigation Strategies

Upgrade OpenSSL to a patched version that includes the fix for CVE-2026-72897. Avoid using SSL_set_SSL_CTX() to switch contexts mid-handshake unless absolutely necessary. Review configurations to ensure provider signature algorithms are consistent across contexts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72897. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart