BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2026
CVE-2026-84783High confidence

Use-After-Free in X.509 Extension Cache Under Concurrent Use

OpenSSL · OpenSSL

7.5HighCVSS 3.1
Recommended action
Within 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityHighOperational priority:High, unchanged from published severity.unchanged

Evidence used

  • No CISA KEV confirmation is currently recorded.
  • The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
  • EPSS is 0.23% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Monitor vendor guidance and exploitation sources for a material change.

Verification

  1. Confirm that the asset runs OpenSSL OpenSSL and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 30 daysRemediation target: Within 180 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Distribution package intelligence

Release-specific package status

Debian findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

4 package states
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Debian trixietrixie · sourceopensslNot affectedDebian marks this release not affected (fixed-version marker 0).Not published in this feedDebian Security Tracker ↗Source updated 9 Oct 2026
Debian bookwormbookworm · sourceopensslNot affectedDebian marks this release not affected (fixed-version marker 0).Not published in this feedDebian Security Tracker ↗Source updated 9 Oct 2026
Debian forkyforky · sourceopensslNot affectedDebian marks this release not affected (fixed-version marker 0).Not published in this feedDebian Security Tracker ↗Source updated 9 Oct 2026
Debian sidsid · sourceopensslNot affectedDebian marks this release not affected (fixed-version marker 0).Not published in this feedDebian Security Tracker ↗Source updated 9 Oct 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

1 current
CVE-2026-84783 · CSAF 2.0 · revision 3 · finalRed Hat Product Securityopenssl: openssl: Denial of Service via race condition in certificate extension caching
81 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub
  • edk2-aarch64 as a component of Red Hat Enterprise Linux 10
  • edk2-ovmf as a component of Red Hat Enterprise Linux 10
  • edk2-tools as a component of Red Hat Enterprise Linux 10
  • edk2-tools-doc as a component of Red Hat Enterprise Linux 10
  • edk2.src as a component of Red Hat Enterprise Linux 10
  • mokutil as a component of Red Hat Enterprise Linux 10
  • openssl as a component of Red Hat Enterprise Linux 10
  • openssl-devel as a component of Red Hat Enterprise Linux 10
  • openssl-libs as a component of Red Hat Enterprise Linux 10
  • openssl-perl as a component of Red Hat Enterprise Linux 10
  • openssl.src as a component of Red Hat Enterprise Linux 10
Summary
A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by initiating concurrent connections to a multi-threaded Transport Layer Security (TLS) client or server verifying certificates. Due to improper synchronization when multiple threads simultaneously decode and cache certificate extensions for a shared Certificate Authority (CA) certificate, cached memory can be freed while still in use by another thread. This use-after-free condition results in an invalid memory read, causing the application to crash.
Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2026-89014

No EUVD known-exploited evidence

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
7.5 · CVSS 3.1
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck

What

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck

Why

The program can continue using memory after it has been released, producing unsafe and attacker-influenceable behaviour.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

What

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck

Why

The program can continue using memory after it has been released, producing unsafe and attacker-influenceable behaviour.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
a network path → Use After Free → disrupt the affected service
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-416 ↗

CWE-416: Use After Free. The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory belongs to the code that operates on the new pointer.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CNoneConfidentiality impact: No direct loss is represented by this metric.INoneIntegrity impact: No direct loss is represented by this metric.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedDenial of serviceCWE-416
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2026-89014Official EUVD mapping

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck

Official EUVD record ↗
BSI · German · WID-SEC-2026-3664FreeBSD Project FreeBSD OS: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in FreeBSD Project FreeBSD OS ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder Denial-of-Service-Zustände zu verursachen.

Official advisory ↗
BSI · German · WID-SEC-2026-3638OpenSSL: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren und einen Denial-of-Service-Zustand zu verursachen.

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-1241Multiples vulnérabilités dans OpenSSL

De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Official advisory ↗
CSIRT Italia · Italian · risolte-vulnerabilita-in-openssl-3Risolte vulnerabilità in OpenSSL

Rilasciati aggiornamenti di sicurezza che sanano 14 vulnerabilità, di cui 4 con gravità "alta", in OpenSSL, software open source per la gestione delle comunicazioni crittografiche. Tali vulnerabilità, qualora sfruttata, potrebbero consentire ad un utente malintenzionato di compromettere la disponibilità del servizio o di accedere ad informazioni sensibili sui sistemi interessati.

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2026-037085OpenSSL ProjectのOpenSSLにおける解放済みメモリの使用に関する脆弱性

問題の概要:複数のスレッドが同じX.509証明書を同時に使用すると、そのキャッシュされた拡張データが、別のスレッドによってまだ使用されている最中に解放されてしまう可能性があります。影響の概要:遠隔の認証されていないピアが、マルチスレッド対応のTLSクライアントや、クライアント証明書を要求するマルチスレッド対応のTLSサーバーをクラッシュさせる可能性があります。この問題は、同じ信頼されたCA証明書に対して最初に構築される証明書チェーンが複数の接続によって同時に構築される場合に発生します。これはUse-After-Freeの読み取りであり、プロセスがクラッシュしサービス拒否(DoS)を引き起こす可能性が高い問題です。CWE: CWE-416:Use After Free説明:OpenSSLは証明書のX.509v3拡張のデコード済み値を、初めて必要になった際にX509オブジェクト内にキャッシュします。OpenSSL 4.0では、このキャッシュは2段階で構築されます。まず証明書に対して読み取りロックを保持した状態で拡張値を計算し、次に書き込みロックを取得して証明書に結果を設定します。読み取りロックは他の読み取り者を排除しないため、複数のスレッドが同じ証明書のキャッシュを同時に計算することが可能です。その後、書き込みロックを取得する各スレッドは自分自身の結果を証明書に設定し、前のスレッドによって設定された値を解放します。しかし、前のスレッドはすでにキャッシュを完了とマークし、呼び出し元にそのポインタを返している場合があるため、呼び出し元が解放済みメモリを読んでしまいます。スレッド間で共有される証明書は、その拡張が初めてデコードされる際に曝露されます。TLSでは、リスクのある証明書はチェーン検証用に提供された信頼されたCA証明書であり、これらはすべての接続で共有され、チェーンが初めて構築される際に拡張がデコードおよびキャッシュされます。ピアから送信される証明書は接続毎に別々にデコードされ共有されないため影響を受けません。TLSクライアントがサーバー証明書を検証する場合やクライアント証明書を要求かつ検証するTLSサーバーの場合において、このUse-After-Freeは同じ信頼されたCAに対して最初のチェーンを複数接続が同時に構築した場合にのみ発生します。FIPS影響:なし。FIPSモジュールはX.509証明書の処理をOpenSSL FIPSモジュールの境界外で行っているため、この影響を受けません。OpenSSL 4.0はこの問題に対して脆弱です。OpenSSL 3.6、3.5、3.4、3.0、1.1.1、および1.0.2は本問題の影響を受けません。OpenSSL 4.0のユーザーはOpenSSL 4.0.3にアップグレードすべきです。本問題は2026年8月27日にTim Becker(Xint.io)によって報告され、2026年8月31日にaydinmercanによる独立した公開報告もありました。修正はBob Beckによって開発されました。報告者はTim Becker(Xint.io)とaydinmercanであり、修正者はBob Beckです。

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
Fixed
Action
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 29 Sept 2026 · Last source change 29 Sept 2026, 16:42 UTC · CWE-416 · Use After Free

CVE recordCVE.org · 5.2
CVSS sourceCISA ADP
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-09-30
European sourceENISA EUVD · EUVD-2026-89014
Product sourceVendor CSAF · Red Hat Product Security
Remediation sourceVendor CSAF · Red Hat Product Security
CWE sourceCNA
NVD statusNVD enriched

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub; edk2-aarch64 as a component of Red Hat Enterprise Linux 10; edk2-ovmf as a component of Red Hat Enterprise Linux 10; edk2-tools as a component of Red Hat Enterprise Linux 10; edk2-tools-doc as a component of Red Hat Enterprise Linux 10; edk2.src as a component of Red Hat Enterprise Linux 10; mokutil as a component of Red Hat Enterprise Linux 10; openssl as a component of Red Hat Enterprise Linux 10; openssl-devel as a component of Red Hat Enterprise Linux 10; openssl-libs as a component of Red Hat Enterprise Linux 10; openssl-perl as a component of Red Hat Enterprise Linux 10; openssl.src as a component of Red Hat Enterprise Linux 10; shim-aa64 as a component of Red Hat Enterprise Linux 10; shim-unsigned-aarch64.src as a component of Red Hat Enterprise Linux 10; shim-unsigned-x64.src as a component of Red Hat Enterprise Linux 10; shim-x64 as a component of Red Hat Enterprise Linux 10; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; AAVMF as a component of Red Hat Enterprise Linux 7; OVMF as a component of Red Hat Enterprise Linux 7; mokutil as a component of Red Hat Enterprise Linux 7; openssl as a component of Red Hat Enterprise Linux 7; openssl-devel as a component of Red Hat Enterprise Linux 7; openssl-libs as a component of Red Hat Enterprise Linux 7; openssl-perl as a component of Red Hat Enterprise Linux 7; openssl-static as a component of Red Hat Enterprise Linux 7; openssl.src as a component of Red Hat Enterprise Linux 7; and 56 more · Fixed: openssl-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-0:3.5.8-0.1.hum1@src as a component of Red Hat Hardened Images; openssl-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-config-fips-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-config-fips-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-devel-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-devel-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-devel-engine-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-devel-engine-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-fips-provider-upstream-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-fips-provider-upstream-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-libs-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-libs-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-perl-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-perl-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl3-0:3.5.8-1.hum1@src as a component of Red Hat Hardened Images; openssl3-devel-0:3.5.8-1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl3-devel-0:3.5.8-1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl3-devel-engine-0:3.5.8-1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl3-devel-engine-0:3.5.8-1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl3-libs-0:3.5.8-1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl3-libs-0:3.5.8-1.hum1@x86_64 as a component of Red Hat Hardened Images
    After
    rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub; edk2-aarch64 as a component of Red Hat Enterprise Linux 10; edk2-ovmf as a component of Red Hat Enterprise Linux 10; edk2-tools as a component of Red Hat Enterprise Linux 10; edk2-tools-doc as a component of Red Hat Enterprise Linux 10; edk2.src as a component of Red Hat Enterprise Linux 10; mokutil as a component of Red Hat Enterprise Linux 10; openssl as a component of Red Hat Enterprise Linux 10; openssl-devel as a component of Red Hat Enterprise Linux 10; openssl-libs as a component of Red Hat Enterprise Linux 10; openssl-perl as a component of Red Hat Enterprise Linux 10; openssl.src as a component of Red Hat Enterprise Linux 10; shim-aa64 as a component of Red Hat Enterprise Linux 10; shim-unsigned-aarch64.src as a component of Red Hat Enterprise Linux 10; shim-unsigned-x64.src as a component of Red Hat Enterprise Linux 10; shim-x64 as a component of Red Hat Enterprise Linux 10; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; AAVMF as a component of Red Hat Enterprise Linux 7; OVMF as a component of Red Hat Enterprise Linux 7; mokutil as a component of Red Hat Enterprise Linux 7; openssl as a component of Red Hat Enterprise Linux 7; openssl-devel as a component of Red Hat Enterprise Linux 7; openssl-libs as a component of Red Hat Enterprise Linux 7; openssl-perl as a component of Red Hat Enterprise Linux 7; openssl-static as a component of Red Hat Enterprise Linux 7; openssl.src as a component of Red Hat Enterprise Linux 7; and 51 more · Fixed: openssl-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-0:3.5.8-0.1.hum1@src as a component of Red Hat Hardened Images; openssl-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-config-fips-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-config-fips-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-devel-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-devel-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-devel-engine-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-devel-engine-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-fips-provider-upstream-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-fips-provider-upstream-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-libs-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-libs-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-perl-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-perl-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl3-0:3.5.8-1.hum1@src as a component of Red Hat Hardened Images; openssl3-devel-0:3.5.8-1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl3-devel-0:3.5.8-1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl3-devel-engine-0:3.5.8-1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl3-devel-engine-0:3.5.8-1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl3-libs-0:3.5.8-1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl3-libs-0:3.5.8-1.hum1@x86_64 as a component of Red Hat Hardened Images
    Red Hat Product Security ↗
  2. BlackTree coverageBlackTree article coverage changed from no BlackTree article to 1 BlackTree article.
    Before
    no BlackTree article
    After
    1 BlackTree article
    BlackTree editorial ↗
  3. Affected versionsThe structured affected or fixed version information changed.
    Before
    OpenSSL: 4.0.0 < 4.0.3 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    OpenSSL: 4.0.0 < 4.0.3 · Fixed: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
    Red Hat Product Security ↗
  4. Affected versionsThe structured affected or fixed version information changed.
    Before
    OpenSSL: 4.0.0 < 4.0.3 · Fixed: No fixed version is explicitly recorded in the structured CVE data.
    After
    OpenSSL: 4.0.0 < 4.0.3 · Fixed: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
    Red Hat Product Security ↗
  5. Vendor guidanceAuthoritative vendor guidance changed from remediation: access.redhat.com/CVE-2026-84783 to remediation: access.redhat.com/CVE-2026-84783.
    Before
    remediation: access.redhat.com/CVE-2026-84783
    After
    remediation: access.redhat.com/CVE-2026-84783
    Red Hat Product Security ↗
  6. Remediation statusRemediation status changed from Awaiting fix to Patch available.
    Before
    Awaiting fix
    After
    Patch available
    Red Hat Product Security ↗
  7. Affected versionsThe structured affected or fixed version information changed.
    Before
    rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub; edk2-aarch64 as a component of Red Hat Enterprise Linux 10; edk2-ovmf as a component of Red Hat Enterprise Linux 10; edk2-tools as a component of Red Hat Enterprise Linux 10; edk2-tools-doc as a component of Red Hat Enterprise Linux 10; edk2.src as a component of Red Hat Enterprise Linux 10; mokutil as a component of Red Hat Enterprise Linux 10; openssl as a component of Red Hat Enterprise Linux 10; openssl-devel as a component of Red Hat Enterprise Linux 10; openssl-libs as a component of Red Hat Enterprise Linux 10; openssl-perl as a component of Red Hat Enterprise Linux 10; openssl.src as a component of Red Hat Enterprise Linux 10; shim-aa64 as a component of Red Hat Enterprise Linux 10; shim-unsigned-aarch64.src as a component of Red Hat Enterprise Linux 10; shim-unsigned-x64.src as a component of Red Hat Enterprise Linux 10; shim-x64 as a component of Red Hat Enterprise Linux 10; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; AAVMF as a component of Red Hat Enterprise Linux 7; OVMF as a component of Red Hat Enterprise Linux 7; mokutil as a component of Red Hat Enterprise Linux 7; openssl as a component of Red Hat Enterprise Linux 7; openssl-devel as a component of Red Hat Enterprise Linux 7; openssl-libs as a component of Red Hat Enterprise Linux 7; openssl-perl as a component of Red Hat Enterprise Linux 7; openssl-static as a component of Red Hat Enterprise Linux 7; openssl.src as a component of Red Hat Enterprise Linux 7; and 59 more
    After
    rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub; edk2-aarch64 as a component of Red Hat Enterprise Linux 10; edk2-ovmf as a component of Red Hat Enterprise Linux 10; edk2-tools as a component of Red Hat Enterprise Linux 10; edk2-tools-doc as a component of Red Hat Enterprise Linux 10; edk2.src as a component of Red Hat Enterprise Linux 10; mokutil as a component of Red Hat Enterprise Linux 10; openssl as a component of Red Hat Enterprise Linux 10; openssl-devel as a component of Red Hat Enterprise Linux 10; openssl-libs as a component of Red Hat Enterprise Linux 10; openssl-perl as a component of Red Hat Enterprise Linux 10; openssl.src as a component of Red Hat Enterprise Linux 10; shim-aa64 as a component of Red Hat Enterprise Linux 10; shim-unsigned-aarch64.src as a component of Red Hat Enterprise Linux 10; shim-unsigned-x64.src as a component of Red Hat Enterprise Linux 10; shim-x64 as a component of Red Hat Enterprise Linux 10; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; AAVMF as a component of Red Hat Enterprise Linux 7; OVMF as a component of Red Hat Enterprise Linux 7; mokutil as a component of Red Hat Enterprise Linux 7; openssl as a component of Red Hat Enterprise Linux 7; openssl-devel as a component of Red Hat Enterprise Linux 7; openssl-libs as a component of Red Hat Enterprise Linux 7; openssl-perl as a component of Red Hat Enterprise Linux 7; openssl-static as a component of Red Hat Enterprise Linux 7; openssl.src as a component of Red Hat Enterprise Linux 7; and 56 more · Fixed: openssl-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-0:3.5.8-0.1.hum1@src as a component of Red Hat Hardened Images; openssl-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-config-fips-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-config-fips-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-devel-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-devel-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-devel-engine-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-devel-engine-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-fips-provider-upstream-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-fips-provider-upstream-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-libs-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-libs-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl-perl-0:3.5.8-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl-perl-0:3.5.8-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl3-0:3.5.8-1.hum1@src as a component of Red Hat Hardened Images; openssl3-devel-0:3.5.8-1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl3-devel-0:3.5.8-1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl3-devel-engine-0:3.5.8-1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl3-devel-engine-0:3.5.8-1.hum1@x86_64 as a component of Red Hat Hardened Images; openssl3-libs-0:3.5.8-1.hum1@aarch64 as a component of Red Hat Hardened Images; openssl3-libs-0:3.5.8-1.hum1@x86_64 as a component of Red Hat Hardened Images
    Red Hat Product Security ↗
  8. ENISA EUVD mappingEUVD-2026-89014 was added to the official ENISA EUVD mapping for this CVE.
    Before
    not recorded
    After
    {"euvdId":"EUVD-2026-89014"}
    ENISA EUVD ↗
  9. Vendor guidanceAuthoritative vendor guidance changed: added patch: github.com/de97a1a54f43edefd43b5084ecac54ecadb33081; added remediation: github.com/de97a1a54f43edefd43b5084ecac54ecadb33081; removed remediation: access.redhat.com/CVE-2026-84783; 1 further additions.
    Before
    remediation: access.redhat.com/CVE-2026-84783
    After
    patch: github.com/de97a1a54f43edefd43b5084ecac54ecadb33081 · remediation: github.com/de97a1a54f43edefd43b5084ecac54ecadb33081 · vendor advisory: openssl-library.org/20260929.txt
    openssl-security@openssl.org ↗
  10. Affected versionsThe structured affected or fixed version information changed.
    Before
    OpenSSL: 4.0.0 < 4.0.3 · Fixed: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
    After
    OpenSSL: 4.0.0 < 4.0.3 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA ↗
  11. SeveritySeverity changed from Unknown to High.
    Before
    Unknown
    After
    High
    CISA ADP ↗
  12. CVSS scoreCVSS score changed from not recorded to 7.5 (CVSS 3.1 · CISA ADP · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
    Before
    not recorded
    After
    7.5 (CVSS 3.1 · CISA ADP · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
    CISA ADP ↗
  13. Catalogue recordCVE added to the BlackTree catalogue.
    CNA ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
CVE published
Fixed release or patch reference recorded
Fixed release recorded from official guidance
Fixed release recorded from official guidance
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2026-84783 · cve.blacktree.nl