Covert Timing Channel in OpenSSL - CVE-2025-9231

 

Covert Timing Channel in OpenSSL - CVE-2025-9231

Published: October 1, 2025


Vulnerability identifier: #VU116214
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2025-9231
CWE-ID: CWE-385
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to timing side-channel in SM2 signature computations on 64 bit ARM platforms. A remote attacker can recover the private key and decrypt data.


Affected software

OpenSSL
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Fedora
FreeBSD
Ubuntu
Basesystem Module
Web and Scripting Module
IBM Cloud Pak System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
AppDynamics NodeJS Agent
LANTIME Operating System Firmware (LTOS)
openssl (Ubuntu package)
openssl (Debian package)
openssl
libopenssl-fips-provider
libopenssl-devel
libopenssl-3-fips-provider-debuginfo
openssl-3-debuginfo
libopenssl-3-fips-provider
libopenssl3
openssl-3-debugsource
libopenssl3-debuginfo
libopenssl-3-fips-provider-32bit-debuginfo
libopenssl3-32bit-debuginfo
libopenssl-3-fips-provider-32bit
libopenssl3-32bit
libopenssl-3-devel
openssl-3
openssl3
nodejs24-docs
nodejs24-debuginfo
npm24
nodejs24
nodejs24-debugsource
nodejs24-devel
IBM Cloud Pak for Multicloud Management

How to mitigate CVE-2025-9231

Install updates from vendor's website.

OpenSSL - addressed in versions 3.2.6, 3.3.5, 3.4.3, 3.5.4
IBM Cloud Pak System - update to 2.3.5.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
LANTIME Operating System Firmware (LTOS) - update to 7.10.004
AppDynamics NodeJS Agent - update to 25.12.1
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm11, 1.0.2g-1ubuntu4.20+esm13, 1.0.2n-1ubuntu5.13+esm2, 1.1.1f-1ubuntu2.24+esm1, 1.1.1-1ubuntu2.1~18.04.23+esm6, 3.0.2-0ubuntu1.20, 3.0.13-0ubuntu3.6, 3.4.1-1ubuntu4
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
openssl (Debian package) - addressed in versions 3.0.17-1~deb12u3, 3.5.1-1+deb13u1
openssl - addressed in versions 3.2.6-2.fc41, 3.2.6-2.fc42
libopenssl-fips-provider - update to 3.5.0-150700.3.4.1
libopenssl-devel - update to 3.5.0-150700.3.4.1
openssl - update to 3.5.0-150700.3.4.1
libopenssl-3-fips-provider-debuginfo - update to 3.5.0-150700.5.45.2
openssl-3-debuginfo - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider - update to 3.5.0-150700.5.45.2
libopenssl3 - update to 3.5.0-150700.5.45.2
openssl-3-debugsource - update to 3.5.0-150700.5.45.2
libopenssl3-debuginfo - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-32bit-debuginfo - update to 3.5.0-150700.5.45.2
libopenssl3-32bit-debuginfo - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-32bit - update to 3.5.0-150700.5.45.2
libopenssl3-32bit - update to 3.5.0-150700.5.45.2
libopenssl-3-devel - update to 3.5.0-150700.5.45.2
openssl-3 - update to 3.5.0-150700.5.45.2
openssl3 - update to 3.5.5-1.1.el8
nodejs24-docs - update to 24.18.1-150700.15.18.1
nodejs24-debuginfo - update to 24.18.1-150700.15.18.1
npm24 - update to 24.18.1-150700.15.18.1
nodejs24 - update to 24.18.1-150700.15.18.1
nodejs24-debugsource - update to 24.18.1-150700.15.18.1
nodejs24-devel - update to 24.18.1-150700.15.18.1

External References

Related Security Bulletins