GPU VulnDB

Database/Kernel, userspace & hypervisor

OpenSSL 4.0: use-after-free in the X.509 extension cache crashes multi-threaded TLS peers

CVSS 7.5CVE-2026-84783Kernel, userspace & hypervisorcurated

Impact

OpenSSL 4.0 builds the cached decode of a certificate's X.509v3 extensions under a read lock and installs it under a write lock, so two threads can build it at once and the second free the values the first is still handing to its caller. The certificates at risk are the shared trusted CA certificates used for chain verification, which every connection touches. A remote unauthenticated peer can crash any multi-threaded TLS client, or a TLS server that requests client certificates, if the first chains to a given CA are built concurrently - which is exactly what happens on process start under load. On a GPU fleet that hits the TLS-terminating daemons operators depend on: inference gateways, registries, metrics collectors and anything doing mTLS between nodes. Availability only; no disclosure or code execution is claimed.

Who can reach it

Any remote peer that can open several TLS connections at once to an affected process, or that a client connects out to. No authentication required. Only OpenSSL 4.0 is affected; 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not.

What to do

Upgrade to OpenSSL 4.0.3 and restart every service linked against the shared library - a package upgrade alone leaves running daemons on the old code. Fleets still on 3.x need no action. The FIPS module is outside the affected code.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.