CVE-2026-45447
OpenSSL OpenSSL, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application...
- CVSS
- 8.8
- EPSS
- 5.24% 91.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.10