CVE detail
CVE-2026-45447
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
24 source links · newest first
Information published.
vendormsrc.microsoft.comJun 13, 2026, 8:02 AM- https://access.redhat.com/errata/RHSA-2026:44438access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:39981access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJun 9, 2026, 5:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2481898bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/security/cve/CVE-2026-45447access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:39012access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:39009access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:36217access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:36215access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:35869access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:34102access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:29197access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:26319access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:26275access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:25239access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:25237access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 9, 2026, 5:17 PM - https://openssl-library.org/news/secadv/20260609.txtopenssl-library.org
No excerpt available.
Vendor Advisoryopenssl-library.orgJun 9, 2026, 5:17 PM No excerpt available.
Exploitgithub.comJun 9, 2026, 5:17 PMNo excerpt available.
Exploitgithub.comJun 9, 2026, 5:17 PMNo excerpt available.
Exploitgithub.comJun 9, 2026, 5:17 PMNo excerpt available.
Exploitgithub.comJun 9, 2026, 5:17 PMNo excerpt available.
Exploitgithub.comJun 9, 2026, 5:17 PMA total of 18 vulnerabilities have been patched in the latest OpenSSL releases, including many that were potentially discovered by AI.
newswww.securityweek.comJun 9, 2026, 4:47 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-57435CVSS 1.7 · Low
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed…
- CVE-2026-53085CVSS 7.8 · High
In the Linux kernel, the following vulnerability has been resolved: bpf: fix mm lifecycle in open-coded task_vma iterator The open-coded task_vma iterator reads task->mm lockles…
- CVE-2026-53033CVSS 7.8 · High
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Take state lock for af_unix iter When a BPF iterator program updates a sockmap, there is a race…
- CVE-2026-53006CVSS 9.8 · Critical
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->h…
- CVE-2026-52976CVSS 7.8 · High
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() Two error handling issues exist in xe_exec_queue_cr…
- CVE-2026-52973CVSS 7.8 · High
In the Linux kernel, the following vulnerability has been resolved: futex: Drop CLONE_THREAD requirement for private default hash alloc Currently need_futex_hash_allocate_defaul…