CVE-2023-0286High· 7.4▾ TwilightA type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 11.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
60%
60% → 62%
Last analysed / modified upstream
A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or cause a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, of which neither needs a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. In this case, this vulnerability is likely only to affect applications that have implemented their own functionality for retrieving CRLs over a network.
openssl: X.400 address type confusion in X.509 GeneralName — rated Important by Red Hat. Released 2023-02-07, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. https://access.redhat.com/errata/RHSA-2023:1438 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. https://access.redhat.com/errata/RHSA-2023:1335 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2024:5136
Workarounds / mitigations:
Affected packages:
cryptography >= 0.8.1, < 39.0.1openssl-src < 111.25.0openssl-src >= 300.0.0, < 300.0.12Patched in:
cryptography 39.0.1openssl-src 111.25.0openssl-src 300.0.12Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44223Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
CVE-2026-79020Medium· 4.3chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-79020)
CVE-2026-63381Medium· 6.6Libevent is an event notification library
CVE-2026-55193High· 8.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-73066High· 7.1Tesseract is an open source OCR engine
CVE-2026-66373High· 7.5Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting…