Database/Kernel, userspace & hypervisor
OpenSSL 4.0: use-after-free in the X.509 extension cache crashes multi-threaded TLS peers
Impact
OpenSSL 4.0 builds the cached decode of a certificate's X.509v3 extensions under a read lock and installs it under a write lock, so two threads can build it at once and the second free the values the first is still handing to its caller. The certificates at risk are the shared trusted CA certificates used for chain verification, which every connection touches. A remote unauthenticated peer can crash any multi-threaded TLS client, or a TLS server that requests client certificates, if the first chains to a given CA are built concurrently - which is exactly what happens on process start under load. On a GPU fleet that hits the TLS-terminating daemons operators depend on: inference gateways, registries, metrics collectors and anything doing mTLS between nodes. Availability only; no disclosure or code execution is claimed.
Who can reach it
Any remote peer that can open several TLS connections at once to an affected process, or that a client connects out to. No authentication required. Only OpenSSL 4.0 is affected; 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not.
What to do
Upgrade to OpenSSL 4.0.3 and restart every service linked against the shared library - a package upgrade alone leaves running daemons on the old code. Fleets still on 3.x need no action. The FIPS module is outside the affected code.
References
Related entries
- OpenSSL QUIC: unthrottled RETIRE_CONNECTION_ID backlog lets a peer force ~400MB of allocationCVE-2026-84784 · OpenSSL QUIC stack (NEW_CONNECTION_ID / RETIRE_CONNECTION_ID handling)High
- Linux kernel SUNRPC: gssx decode error paths NULL-deref and leak group_info on the NFS serverCVE-2026-89544 · Linux kernel nfsd/SUNRPC gssx option-array decoder (gss-proxy upcall)High
- Linux kernel nfsd: transports routed to threadless service pools hang the connection indefinitelyCVE-2026-89549 · Linux kernel SUNRPC svc_pool_for_cpu() (nfsd pool-to-CPU routing)High
- Linux kernel nfsd: broken short-write detection writes the next segment at the wrong file offsetCVE-2026-89678 · Linux kernel nfsd_direct_write() (NFS server direct-I/O write path)High
- Linux kernel nfsd: NFSv4 SETATTR with the special ONE stateid NULL-derefs and oopses the serverCVE-2026-89679 · Linux kernel nfsd4_setattr() (NFSv4 delegated timestamp attributes)High
- Linux kernel nfsd: each failed inter-server COPY leaks an nfsd_file, pinning inode and mountCVE-2026-89680 · Linux kernel nfsd4_copy() (inter-server COPY setup error path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.