{
  "metadata": {
    "@context": "https://openvex.dev/ns/v0.2.0",
    "@id": "https://packages.broadcom.com/photon/photon_cve_metadata/cve/2026/CVE-2026-42767",
    "author": "VMware Photon OS",
    "timestamp": "2026-06-20T05:34:28.606776",
    "version": 1
  },
  "statements": [
    {
      "vulnerability": {
        "@id": "https://nvd.nist.gov/vuln/detail/CVE-2026-42767",
        "name": "CVE-2026-42767"
      },
      "products": [
        {
          "@id": "pkg:rpm/photon/openssl@3.5.7-1.ph5?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl@3.5.7-1.ph5?arch=aarch64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-libs@3.5.7-1.ph5?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-libs@3.5.7-1.ph5?arch=aarch64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-devel@3.5.7-1.ph5?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-devel@3.5.7-1.ph5?arch=aarch64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-perl@3.5.7-1.ph5?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-perl@3.5.7-1.ph5?arch=aarch64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-c_rehash@3.5.7-1.ph5?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-c_rehash@3.5.7-1.ph5?arch=aarch64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-docs@3.5.7-1.ph5?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-docs@3.5.7-1.ph5?arch=aarch64"
        }
      ],
      "status": "fixed",
      "status_notes": "The vulnerable function OSSL_CRMF_ENCRYPTEDVALUE_decrypt() does not exist in 3.0.x. Only OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert() is present. The decrypt variant was added to CRMF after 3.0."
    },
    {
      "vulnerability": {
        "@id": "https://nvd.nist.gov/vuln/detail/CVE-2026-42767",
        "name": "CVE-2026-42767"
      },
      "products": [
        {
          "@id": "pkg:rpm/photon/openssl?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl?arch=aarch64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-devel?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-devel?arch=aarch64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-perl?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-perl?arch=aarch64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-c_rehash?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-c_rehash?arch=aarch64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-docs?arch=x86_64"
        },
        {
          "@id": "pkg:rpm/photon/openssl-docs?arch=aarch64"
        }
      ],
      "status": "not_affected",
      "status_notes": "The vulnerable function OSSL_CRMF_ENCRYPTEDVALUE_decrypt() does not exist in 3.0.x. Only OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert() is present. The decrypt variant was added to CRMF after 3.0."
    }
  ]
}