Vulnerability record · CVE-2021-4044 · published 14 December 2021
CVE-2021-4044: OpenSSL libssl mishandles negative X509_verify_cert return, causing denial of service
OOpenssl · Openssl
OpenSSL 3.0.0 libssl mishandles a negative return value from X509_verify_cert() during client-side server certificate verification, causing SSL_get_error() to return the unexpected SSL_ERROR_WANT_RETRY_VERIFY. Applications that do not set SSL_CTX_set_cert_verify_callback() may crash, loop, or otherwise misbehave. Combined with a separate OpenSSL 3.0 bug that makes X509_verify_cert() report an internal error on valid chains lacking a Subject Alternative Name under enforced name constraints, an attacker can trigger this behavior remotely.
Description
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as SSL_connect() or SSL_do_handshake()) to not indicate success and a subsequent call to SSL_get_error() to return the value SSL_ERROR_WANT_RETRY_VERIFY. This return value is only supposed to be returned by OpenSSL if the application has previously called SSL_CTX_set_cert_verify_callback(). Since most applications do not do this the SSL_ERROR_WANT_RETRY_VERIFY return value from SSL_get_error() will be totally unexpected and applications may not behave correctly as a result. The exact behaviour will depend on the application but it could result in crashes, infinite loops or other similar incorrect responses. This issue is made more serious in combination with a separate bug in OpenSSL 3.0 that will cause X509_verify_cert() to indicate an internal error when processing a certificate chain. This will occur where a certificate does not include the Subject Alternative Name extension but where a Certificate Authority has enforced name constraints. This issue can occur even with valid chains. By combining the two issues an attacker could induce incorrect, application dependent behaviour. Fixed in OpenSSL 3.0.1 (Affected 3.0.0).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated denial of service with high EPSS and a CVSS of 7.5, though no confirmed exploitation or KEV listing.
What it is
OpenSSL 3.0.0 libssl mishandles a negative return value from X509_verify_cert() during client-side server certificate verification, causing SSL_get_error() to return the unexpected SSL_ERROR_WANT_RETRY_VERIFY. Applications that do not set SSL_CTX_set_cert_verify_callback() may crash, loop, or otherwise misbehave. Combined with a separate OpenSSL 3.0 bug that makes X509_verify_cert() report an internal error on valid chains lacking a Subject Alternative Name under enforced name constraints, an attacker can trigger this behavior remotely.
Impact
An attacker can induce application-dependent incorrect behavior such as crashes or infinite loops, producing a denial of service against TLS clients. No confidentiality or integrity impact is described; the CVSS vector rates availability impact as high.
Attack surface
Reached over the network via a malicious or malformed server certificate presented during the TLS handshake; the vector shows no privileges or user interaction required. The client application must be using OpenSSL 3.0.0 libssl and not have set a custom certificate verification callback.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is documented in the record. EPSS is high (0.50099, 98.8th percentile), indicating elevated predicted exploitation likelihood, but the record provides no confirmed in-the-wild activity.
What to do
- Upgrade OpenSSL to 3.0.1 or later, which fixes the issue.
- Inventory and update downstream products bundling OpenSSL 3.0.0, including NetApp software and Node.js builds, per vendor advisories.
- Where immediate upgrade is not possible, set SSL_CTX_set_cert_verify_callback() so the unexpected SSL_ERROR_WANT_RETRY_VERIFY return is handled explicitly.
- Ensure client applications handle unexpected SSL_get_error() values defensively rather than assuming only documented returns.
- Monitor vendor advisories for updated affected product versions and re-scan for OpenSSL 3.0.0 components.
Detection
- Search hosts and container images for OpenSSL 3.0.0 libraries and linked applications.
- Monitor TLS client processes for abnormal crashes, hangs, or infinite loops during handshake with external servers.
- Log and alert on SSL_ERROR_WANT_RETRY_VERIFY occurrences in application logs where the callback was not configured.
- Correlate outbound TLS connection failures with servers presenting certificate chains lacking Subject Alternative Name under name constraints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-4044 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-4044), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.