Skip to content

Commit 14340b7

Browse files
n13lt8m
authored andcommitted
Fix NULL Dereference in Certificate Verification with OCSP Checking
When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens. This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue. Fixes CVE-2026-42765 Reviewed-by: Neil Horman <nhorman@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> MergeDate: Mon Jun 8 18:55:29 2026 (cherry picked from commit 1b5b3379bad0aaff7ed21096c28872dc19ad3cbc)
1 parent bf29a45 commit 14340b7

1 file changed

Lines changed: 10 additions & 0 deletions

File tree

‎crypto/x509/x509_vfy.c‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1200,6 +1200,16 @@ static int check_revocation(X509_STORE_CTX *ctx)
12001200

12011201
/* the issuer certificate is the next in the chain */
12021202
ctx->current_issuer = sk_X509_value(ctx->chain, i + 1);
1203+
if (ctx->current_issuer == NULL) {
1204+
/*
1205+
* No issuer exists at i+1 — this is the partial-chain
1206+
* trust anchor. OCSP requires an issuer to build the
1207+
* CertID, so skip OCSP checking for this certificate.
1208+
*/
1209+
if ((ctx->param->flags & X509_V_FLAG_PARTIAL_CHAIN) != 0)
1210+
continue;
1211+
return verify_cb_ocsp(ctx, X509_V_ERR_OCSP_VERIFY_FAILED);
1212+
}
12031213

12041214
ok = check_cert_ocsp_resp(ctx);
12051215

0 commit comments

Comments
 (0)