CVE-2026-28388
OpenSSL OpenSSL, SIMATIC CN 4100, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL poi...
- CVSS
- 7.5
- EPSS
- 1.06% 61.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.08