| Summary | Issue summary: A specially crafted password-encrypted CMS message Impact summary: This NULL pointer dereference leads to an application crash The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as An attacker who supplies such a CMS message to an application performing Applications that process password-encrypted CMS messages may be affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this |
|---|---|
| Publication Date | June 10, 2026, 2:17 a.m. |
| Registration Date | June 10, 2026, 4:17 a.m. |
| Last Update | June 10, 2026, 2:17 a.m. |