Database/Kernel, userspace & hypervisor
OpenSSL CMP client: NULL dereference when revoking a certificate by PKCS#10 CSR
Impact
A CMP client that revokes a certificate by supplying a PKCS#10 CSR (openssl cmp -cmd rr -csr, or OSSL_CMP_CTX_set1_p10CSR()) sends no issuer name or serial number, so it has nothing to compare against when the server names the revoked certificate in its response. A crafted name makes the client read from a NULL pointer and terminate. Where this reaches a GPU fleet is certificate automation: a CMP-based enrolment or revocation job that crashes leaves the workflow stuck rather than exposing anything, and the blast radius is the client process, not the node. The response is authenticated before the affected code runs, so the attacker must be the CMP server itself, a compromised one, or a man-in-the-middle holding the message-protection secret - a high bar. Clients that identify the certificate by the certificate itself or by issuer and serial number are not affected, and the FIPS module is out of scope.
Who can reach it
Requires a malicious or compromised CMP server, or a man-in-the-middle in possession of the CMP message-protection secret, and a client that revokes using a PKCS#10 CSR. Not reachable by an unauthenticated network attacker.
What to do
Update the distribution's OpenSSL packages per the 2026-09-29 OpenSSL advisory and restart anything long-running that uses the CMP client; one-shot CLI invocations pick up the fix on next run. No reboot needed, and fixed version numbers are in the vendor advisory rather than the NVD record. Avoiding the CSR form of revocation - identifying the certificate by issuer and serial - sidesteps the code path entirely.
References
Related entries
- libuser: direct /etc/passwd rewrites can corrupt the account database and chain to local rootCVE-2015-3246 · libuser / usermode userhelper (/etc/passwd modification on RHEL)Medium
- Linux KVM/SVM - missing sev_decommission in sev_receive_start: KVM failed to DECOMMISSION the current SEV contextCVE-2021-47389 · Linux KVM/SVM - missing sev_decommission in sev_receive_startMedium
- QEMU VMDK driver: a crafted image causes an out-of-bounds read leaking 12 bytes or crashing the processCVE-2026-2243 · QEMU VMDK block driver (out-of-bounds read while parsing the image)Medium
- Linux kernel (drivers/iommu/amd): AMD-Vi updated the domain's I/O page-table mode before running the code that freesCVE-2022-48904 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): Unbinding a PASID races the I/O page-fault (PPR) notifications still in flightCVE-2023-53501 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/iommufd): The vfio type1 info structure is not zeroed before being filled and copied outCVE-2023-54034 · Linux kernel (drivers/iommu/iommufd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.