CVE-2020-1967: Broadcom Fabric Operating System

High severity, CVSS 7.5. EPSS: 53.3% chance of exploitation in the next 30 days.

Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).

Affected products

  • Broadcom Fabric Operating System: affected versions not specified
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
  • Freebsd Freebsd: version 12.1 only
  • Jdedwards Enterpriseone: before 9.2.5.0 (fixed in 9.2.5.0)
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp E-Series Performance Analyzer: affected versions not specified
  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Smi-S Provider: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • OpenSSL OpenSSL: from 1.1.1d, up to and including 1.1.1f
  • Opensuse Leap: version 15.1 only; version 15.2 only
  • Oracle Application Server: version 12.1.3 only
  • Oracle Enterprise Manager Base Platform: version 13.4.0.0 only
  • Oracle Enterprise Manager For Storage Management: version 13.3.0.0 only; version 13.4.0.0 only
  • Oracle Enterprise Manager Ops Center: version 12.4.0 only
  • Oracle HTTP Server: version 12.2.1.4.0 only
  • Oracle Jd Edwards World Security: version a9.4 only
  • Oracle MySQL: up to and including 5.6.48; from 5.7.0, up to and including 5.7.30; from 8.0.0, up to and including 8.0.20
  • Oracle MySQL Connectors: up to and including 8.0.20
  • Oracle MySQL Enterprise Monitor: up to and including 4.0.12; from 8.0.0, up to and including 8.0.20
  • Oracle MySQL Workbench: up to and including 8.0.21
  • Oracle PeopleSoft Enterprise PeopleTools: version 8.56 only; version 8.57 only; version 8.58 only; version 8.59 only
  • and 1 more

Published 2020-04-21. Last modified 2026-10-08.