maintenance release of the cryptographic library , which addresses (), leading to a denial of service when trying to negotiate a TLS 1.3 connection with a maliciously controlled server or client. The vulnerability has been assigned a high severity level.
The issue only occurs in applications using the SSL_check_chain() function, resulting in a process crash when TLS extension "signature_algorithms_cert" is misused. Specifically, receiving an unsupported or incorrect value for the digital signature algorithm during the connection negotiation causes a null pointer dereference and a process crash. The problem manifests starting from OpenSSL version 1.1.1d.
Source: opennet.ru
