Stack-based buffer overflow in OpenSSL - CVE-2025-11187
Published: January 27, 2026
Vulnerability identifier: #VU122075
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-11187
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when parsing PKCS#12 files. A remote attacker can pass a specially crafted PKCS#12 file to the application, trigger a stack-based buffer overflow and perform a denial of service attack.
Affected software
OpenSSL
Debian Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Micro
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
FreeBSD
Ubuntu
SUSE Linux Enterprise Live Patching
openSUSE Leap
Fedora
SecurityCenter
Netezza Appliance
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM MQ
AppDynamics NodeJS Agent
LANTIME Operating System Firmware (LTOS)
openssl-3-livepatches-debugsource
openssl-3-livepatches
openssl-3-livepatches-debuginfo
openssl (Ubuntu package)
openssl (Debian package)
openssl (Red Hat package)
openssl
libopenssl-3-fips-provider-debuginfo
openssl-3
openssl-3-debugsource
openssl-3-debuginfo
libopenssl-3-fips-provider
libopenssl-3-devel
libopenssl3
libopenssl3-debuginfo
Debian Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Micro
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
FreeBSD
Ubuntu
SUSE Linux Enterprise Live Patching
openSUSE Leap
Fedora
SecurityCenter
Netezza Appliance
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM MQ
AppDynamics NodeJS Agent
LANTIME Operating System Firmware (LTOS)
openssl-3-livepatches-debugsource
openssl-3-livepatches
openssl-3-livepatches-debuginfo
openssl (Ubuntu package)
openssl (Debian package)
openssl (Red Hat package)
openssl
libopenssl-3-fips-provider-debuginfo
openssl-3
openssl-3-debugsource
openssl-3-debuginfo
libopenssl-3-fips-provider
libopenssl-3-devel
libopenssl3
libopenssl3-debuginfo
How to mitigate CVE-2025-11187
Install updates from vendor's website.
OpenSSL - addressed in versions 3.4.4, 3.5.5, 3.6.1
SecurityCenter - addressed in versions SC202607.1, SC202607.2
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
LANTIME Operating System Firmware (LTOS) - update to 7.10.008
IBM MQ - addressed in versions 9.1.0.34, 9.2.0.41, 9.3.0.37, 9.4.0.20
AppDynamics NodeJS Agent - update to 25.12.1
openssl-3-livepatches-debugsource - addressed in versions 0.4-150600.13.11.1, 0.4-150700.16.6.1
openssl-3-livepatches - addressed in versions 0.4-150600.13.11.1, 0.4-150700.16.6.1
openssl-3-livepatches-debuginfo - addressed in versions 0.4-150600.13.11.1, 0.4-150700.16.6.1
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.0.2n-1ubuntu5.13+esm3, 1.1.1f-1ubuntu2.24+esm2, 1.1.1-1ubuntu2.1~18.04.23+esm7, 3.0.2-0ubuntu1.21, 3.0.13-0ubuntu3.7, 3.5.3-1ubuntu3
openssl (Debian package) - addressed in versions 3.0.18-1~deb12u2, 3.5.4-1~deb13u2
openssl (Red Hat package) - addressed in versions 3.2.2-16.el10_0.6, 3.5.1-7.el9_7, 3.5.1-7.el10_1
openssl - addressed in versions 3.2.6-3.fc42, 3.5.4-2.fc43
libopenssl-3-fips-provider-debuginfo - update to 3.5.0-160000.5.1
openssl-3 - update to 3.5.0-160000.5.1
openssl-3-debugsource - update to 3.5.0-160000.5.1
openssl-3-debuginfo - update to 3.5.0-160000.5.1
libopenssl-3-fips-provider - update to 3.5.0-160000.5.1
libopenssl-3-devel - update to 3.5.0-160000.5.1
libopenssl3 - update to 3.5.0-160000.5.1
libopenssl3-debuginfo - update to 3.5.0-160000.5.1
SecurityCenter - addressed in versions SC202607.1, SC202607.2
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
LANTIME Operating System Firmware (LTOS) - update to 7.10.008
IBM MQ - addressed in versions 9.1.0.34, 9.2.0.41, 9.3.0.37, 9.4.0.20
AppDynamics NodeJS Agent - update to 25.12.1
openssl-3-livepatches-debugsource - addressed in versions 0.4-150600.13.11.1, 0.4-150700.16.6.1
openssl-3-livepatches - addressed in versions 0.4-150600.13.11.1, 0.4-150700.16.6.1
openssl-3-livepatches-debuginfo - addressed in versions 0.4-150600.13.11.1, 0.4-150700.16.6.1
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.0.2n-1ubuntu5.13+esm3, 1.1.1f-1ubuntu2.24+esm2, 1.1.1-1ubuntu2.1~18.04.23+esm7, 3.0.2-0ubuntu1.21, 3.0.13-0ubuntu3.7, 3.5.3-1ubuntu3
openssl (Debian package) - addressed in versions 3.0.18-1~deb12u2, 3.5.4-1~deb13u2
openssl (Red Hat package) - addressed in versions 3.2.2-16.el10_0.6, 3.5.1-7.el9_7, 3.5.1-7.el10_1
openssl - addressed in versions 3.2.6-3.fc42, 3.5.4-2.fc43
libopenssl-3-fips-provider-debuginfo - update to 3.5.0-160000.5.1
openssl-3 - update to 3.5.0-160000.5.1
openssl-3-debugsource - update to 3.5.0-160000.5.1
openssl-3-debuginfo - update to 3.5.0-160000.5.1
libopenssl-3-fips-provider - update to 3.5.0-160000.5.1
libopenssl-3-devel - update to 3.5.0-160000.5.1
libopenssl3 - update to 3.5.0-160000.5.1
libopenssl3-debuginfo - update to 3.5.0-160000.5.1
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Ubuntu update for openssl
- Fedora 43 update for openssl
- Fedora 42 update for openssl
- Ubuntu update for openssl
- Debian update for openssl
- Red Hat Enterprise Linux 10 update for openssl
- Red Hat Enterprise Linux 9 update for openssl
- Red Hat Enterprise Linux 10 update for openssl
- SUSE update for openssl-3
- Meinberg LANTIME firmware update for third-party components
- Multiple vulnerabilities in IBM MQ
- Splunk AppDynamics NodeJS Agent update for third-party components
- FreeBSD update for OpenSSL
- Multiple vulnerabilities in IBM Netezza Appliance
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- SUSE update for openssl-3-livepatches
- SUSE update for openssl-3-livepatches
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in Tenable Security Center
- Tenable Security Center on Enclave Security update for third-party components