---
id: CVE-2026-45447
title: |-
  Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
  trigger a use-after-free during PKCS#7 signature verification.

  Impact summary: A use-after-free may result in process crashes, heap
  corruption, or potentially remo…
summary: |-
  Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
  trigger a use-after-free during PKCS#7 signature verification.

  Impact summary: A use-after-free may result in process crashes, heap
  corruption, or potentially remo…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
  - CWE-825
vendor: openssl
product: openssl
affected:
  - 'openssl >= 1.0.2, < 1.0.2zq'
  - 'openssl >= 1.1.1, < 1.1.1zh'
  - 'openssl >= 3.0.0, < 3.0.21'
  - 'openssl >= 3.4.0, < 3.4.6'
  - 'openssl >= 3.5.0, < 3.5.7'
  - 'openssl >= 3.6.0, < 3.6.3'
  - openssl = 4.0.0
patched:
  - openssl 3.6.3
published: '2026-06-09'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:18:26.343'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45447'
references:
  - url: >-
      https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c
    label: openssl-security@openssl.org
  - url: >-
      https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8
    label: openssl-security@openssl.org
  - url: >-
      https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54
    label: openssl-security@openssl.org
  - url: >-
      https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c
    label: openssl-security@openssl.org
  - url: >-
      https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e
    label: openssl-security@openssl.org
  - url: 'https://openssl-library.org/news/secadv/20260609.txt'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2026:25237'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25239'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26275'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26319'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:29197'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34102'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:35869'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36215'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36217'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:39009'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:39012'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:39981'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:44438'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:47735'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:47737'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:58563'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:58981'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:59831'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:66524'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-45447'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2481898'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-45447'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45447'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67551'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42825'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59641'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59635'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55543'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62562'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62790'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62563'
tags:
  - nvd
  - exploit-available
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.03566
epssPercentile: 0.88851
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/0xBlackash/CVE-2026-45447'
    - 'https://github.com/HORKimhab/CVE-2026-45447'
  checkedAt: '2026-09-24T07:53:04.100Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-10T03:59:38.212378Z'
scores:
  nvd: 8.8
  vendor: 8.1
  adp: 8.8
ingestedAt: '2026-07-06T17:44:51.182Z'
---

## Overview

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
trigger a use-after-free during PKCS#7 signature verification.

Impact summary: A use-after-free may result in process crashes, heap
corruption, or potentially remote code execution.

When processing a PKCS#7 or S/MIME signed message, if the SignedData
digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may
incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent
use of the BIO by the calling application results in a use-after-free
condition.

In the common case this occurs when the application later calls
BIO_free() on the BIO originally passed to PKCS7_verify(). Depending
on allocator behavior and application-specific BIO usage patterns, this
may result in a crash or other memory corruption. In some application
contexts this may potentially be exploitable for remote code execution.

Applications that process PKCS#7 or S/MIME signed messages using OpenSSL
PKCS#7 APIs may be affected. Applications using the CMS APIs for this
processing are not affected.

The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.

## Affected

- `openssl >= 1.0.2, < 1.0.2zq`
- `openssl >= 1.1.1, < 1.1.1zh`
- `openssl >= 3.0.0, < 3.0.21`
- `openssl >= 3.4.0, < 3.4.6`
- `openssl >= 3.5.0, < 3.5.7`
- `openssl >= 3.6.0, < 3.6.3`
- `openssl = 4.0.0`

## Remediation

Upgrade past the affected range:

- `openssl 3.6.3`

## Vendor advisories

- **RHSA-2026:66524** · Red Hat · fixed in: Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION), Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION) · released 2026-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:66524)
- **RHSA-2026:58563** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58563)
- **RHSA-2026:59831** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:59831)
- **RHSA-2026:25237** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-06-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:25237)
- **RHSA-2026:36215** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:36215)
- **RHSA-2026:36217** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-07-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:36217)
- **RHSA-2026:39012** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-07-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:39012)
- **RHSA-2026:39009** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-07-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:39009)
- **RHSA-2026:35869** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:35869)
- **RHSA-2026:44438** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44438)
- **RHSA-2026:25239** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-06-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:25239)
- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json)
