Disclosure summary
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
Source-reported weakness categories
CWE-476
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2020-1967
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| openssl | openssl | * {"versionStartIncluding":"1.1.1d","versionEndIncluding":"1.1.1f"} |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| freebsd | freebsd | 12.1 |
| fedoraproject | fedora | 30 |
| fedoraproject | fedora | 31 |
| fedoraproject | fedora | 32 |
| oracle | application_server | 12.1.3 |
| oracle | enterprise_manager_base_platform | 13.4.0.0 |
| oracle | enterprise_manager_for_storage_management | 13.3.0.0 |
| oracle | enterprise_manager_for_storage_management | 13.4.0.0 |
| oracle | enterprise_manager_ops_center | 12.4.0 |
| oracle | http_server | 12.2.1.4.0 |
| oracle | jd_edwards_world_security | a9.4 |
| oracle | mysql | * {"versionStartIncluding":"8.0.0","versionEndIncluding":"8.0.20"} |
| oracle | mysql_connectors | * {"versionEndIncluding":"8.0.20"} |
| oracle | mysql_enterprise_monitor | * {"versionStartIncluding":"8.0.0","versionEndIncluding":"8.0.20"} |
| oracle | mysql_workbench | * {"versionEndIncluding":"8.0.21"} |
| oracle | peoplesoft_enterprise_peopletools | 8.56 |
| oracle | peoplesoft_enterprise_peopletools | 8.57 |
| oracle | peoplesoft_enterprise_peopletools | 8.58 |
| oracle | peoplesoft_enterprise_peopletools | 8.59 |
| netapp | active_iq_unified_manager | * {"versionStartIncluding":"7.3"} |
| netapp | active_iq_unified_manager | * {"versionStartIncluding":"9.5"} |
| netapp | e-series_performance_analyzer | - |
| netapp | oncommand_insight | - |
| netapp | oncommand_workflow_automation | - |
| netapp | smi-s_provider | - |
| netapp | snapcenter | - |
| netapp | steelstore_cloud_integrated_storage | - |
| broadcom | fabric_operating_system | - |
| opensuse | leap | 15.1 |
| opensuse | leap | 15.2 |
| jdedwards | enterpriseone | * {"versionEndExcluding":"9.2.5.0"} |
| tenable | log_correlation_engine | * {"versionEndExcluding":"6.0.9"} |
Original records & references
- NIST NVD record
- CVE Program record
- git.openssl.org
- github.com — Exploit, Third Party Advisory
- kb.pulsesecure.net — Third Party Advisory
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- security.FreeBSD.org — Patch, Third Party Advisory
- security.gentoo.org — Third Party Advisory
- security.netapp.com — Third Party Advisory
- security.netapp.com — Third Party Advisory
- www.debian.org — Third Party Advisory
- www.openssl.org — Vendor Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.synology.com — Third Party Advisory
- www.synology.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- git.openssl.org
- github.com — Exploit, Third Party Advisory
- kb.pulsesecure.net — Third Party Advisory
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- security.FreeBSD.org — Patch, Third Party Advisory
- security.gentoo.org — Third Party Advisory
- security.netapp.com — Third Party Advisory
- security.netapp.com — Third Party Advisory
- www.debian.org — Third Party Advisory
- www.openssl.org — Vendor Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.synology.com — Third Party Advisory
- www.synology.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
- www.tenable.com — Third Party Advisory
PUBLISHED 2020-04-21T10:15:11-04:00
MODIFIED 2026-10-08T17:17:24-04:00
INGESTED 2026-10-10T20:50:19-04:00