Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted signature_algorithms_cert TLS extension.
Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible.
CWE: CWE-476: NULL Pointer Dereference
Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA).
When the private key is configured along with a matching certificate, the signature_algorithms_cert extension is handled reliably even without the fix, and peer clients or servers that dont support raw public keys may be able to complete a TLS connection by pinning or verifying the corresponding certificate or its public key.
Deployments that prefer to configure just a private key with no certificate need to upgrade to an updated release as noted below.
FIPS impact: no
No FIPS modules are affected by this issue, as the SSL protocol implementation is outside the OpenSSL FIPS module boundary.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Openssl | Openssl | 3.4.0 (including) | 3.4.7 (excluding) |
| Openssl | Openssl | 3.5.0 (including) | 3.5.8 (excluding) |
| Openssl | Openssl | 3.6.0 (including) | 3.6.4 (excluding) |
| Openssl | Openssl | 4.0.0 (including) | 4.0.2 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | openssl-1:3.5.8-1.el10_2 | * |
| Red Hat Enterprise Linux 9 | RedHat | openssl-1:3.5.8-1.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | openssl-1:3.5.8-1.el9_8 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/jetstack-cert-manager-rhel9:1790223279 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-istio-csr-rhel9:1790223719 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-operator-rhel9:1790272426 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/jetstack-cert-manager-acmesolver-rhel9:1790589998 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/jetstack-cert-manager-rhel9:1790589912 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-istio-csr-rhel9:1790589914 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-operator-rhel9:1790589855 | * |
| Red Hat Hardened Images | RedHat | openssl3-main-3.5.8-0.1.hum1 | * |
| Red Hat Hardened Images | RedHat | openssl-main-3.5.8-0.1.hum1 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-kubernetes-rhel9:1789479916 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1789482961 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1790241954 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:1790241900 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1790242004 | * |
| Openssl | Ubuntu | devel | * |
| Openssl | Ubuntu | resolute | * |
| Openssl | Ubuntu | upstream | * |