Skip to content

Commit d35cd47

Browse files
bob-beckt8m
authored andcommitted
Use the correct issuer when validating rootCAKeyUpdate
This correctly uses the existing root, and not the same certificate as the root of the chain to validate. While we are here, we also turn on self signed certificate signature checking as this case is actually bringing in trust anchors as self signed certs, and fix a possible NULL deref. Fixes CVE-2026-42769 Reviewed-by: Neil Horman <nhorman@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> MergeDate: Mon Jun 8 19:54:01 2026 (cherry picked from commit 8b6c5dacb6ade54f30778cf344600d4a9df1f032)
1 parent a2ca7b2 commit d35cd47

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

‎crypto/cmp/cmp_genm.c‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -203,7 +203,7 @@ static int selfsigned_verify_cb(int ok, X509_STORE_CTX *store_ctx)
203203
for (i = 0; i < sk_X509_num(trust); i++) {
204204
issuer = sk_X509_value(trust, i);
205205
if ((*check_issued)(store_ctx, cert, issuer)) {
206-
if (X509_add_cert(chain, cert, X509_ADD_FLAG_UP_REF))
206+
if (X509_add_cert(chain, issuer, X509_ADD_FLAG_UP_REF))
207207
ok = 1;
208208
break;
209209
}
@@ -236,6 +236,7 @@ static int verify_ss_cert(OSSL_LIB_CTX *libctx, const char *propq,
236236
if ((csc = X509_STORE_CTX_new_ex(libctx, propq)) == NULL
237237
|| !X509_STORE_CTX_init(csc, ts, target, untrusted))
238238
goto err;
239+
X509_STORE_CTX_set_flags(csc, X509_V_FLAG_CHECK_SS_SIGNATURE);
239240
X509_STORE_CTX_set_verify_cb(csc, selfsigned_verify_cb);
240241
ok = X509_verify_cert(csc) > 0;
241242

@@ -254,7 +255,8 @@ verify_ss_cert_trans(OSSL_CMP_CTX *ctx, X509 *trusted /* may be NULL */,
254255
int res = 0;
255256

256257
if (trusted != NULL) {
257-
X509_VERIFY_PARAM *vpm = X509_STORE_get0_param(ts);
258+
X509_VERIFY_PARAM *vpm = (ts == NULL) ? NULL
259+
: X509_STORE_get0_param(ts);
258260

259261
if ((ts = X509_STORE_new()) == NULL)
260262
return 0;

0 commit comments

Comments
 (0)