GPU VulnDB

Database/Kernel, userspace & hypervisor

OpenSSL CMP client: NULL dereference when revoking a certificate by PKCS#10 CSR

CVSS 5.3CVE-2026-75805Kernel, userspace & hypervisorcurated

Impact

A CMP client that revokes a certificate by supplying a PKCS#10 CSR (openssl cmp -cmd rr -csr, or OSSL_CMP_CTX_set1_p10CSR()) sends no issuer name or serial number, so it has nothing to compare against when the server names the revoked certificate in its response. A crafted name makes the client read from a NULL pointer and terminate. Where this reaches a GPU fleet is certificate automation: a CMP-based enrolment or revocation job that crashes leaves the workflow stuck rather than exposing anything, and the blast radius is the client process, not the node. The response is authenticated before the affected code runs, so the attacker must be the CMP server itself, a compromised one, or a man-in-the-middle holding the message-protection secret - a high bar. Clients that identify the certificate by the certificate itself or by issuer and serial number are not affected, and the FIPS module is out of scope.

Who can reach it

Requires a malicious or compromised CMP server, or a man-in-the-middle in possession of the CMP message-protection secret, and a client that revokes using a PKCS#10 CSR. Not reachable by an unauthenticated network attacker.

What to do

Update the distribution's OpenSSL packages per the 2026-09-29 OpenSSL advisory and restart anything long-running that uses the CMP client; one-shot CLI invocations pick up the fix on next run. No reboot needed, and fixed version numbers are in the vendor advisory rather than the NVD record. Avoiding the CSR form of revocation - identifying the certificate by issuer and serial - sidesteps the code path entirely.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.