Stack-based buffer overflow in OpenSSL - CVE-2025-15467

 

Stack-based buffer overflow in OpenSSL - CVE-2025-15467

Published: January 27, 2026 / Updated: April 22, 2026


Vulnerability identifier: #VU122076
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-15467
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters. A remote attacker can supply a specially crafted CMS message with an oversized IV, trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

OpenSSL
SUSE Linux Enterprise Server 15 SP6
Debian Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Micro
IBM i
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
FreeBSD
Ubuntu
SUSE Linux Enterprise Live Patching
Basesystem Module
openSUSE Leap
Anolis OS
openEuler
SecurityCenter
Netezza Appliance
IBM OS Image for Red Hat Linux Systems
Oracle Business Intelligence Enterprise Edition
IBM Security Verify Directory
Integration Bus for z/OS
NativeEdge Orchestrator
IBM Cloud Pak System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM MQ
Oracle Communications Cloud Native Core Certificate Management
AppDynamics NodeJS Agent
Service Interconnect
Communications Unified Assurance
FortiPortal
FortiNAC-F
LANTIME Operating System Firmware (LTOS)
MySQL Server
IBM InfoSphere Information Server
MySQL Enterprise Backup
Red Hat OpenShift Container Platform
MySQL Workbench
IBM App Connect Enterprise
Oracle Autonomous Health Framework
PeopleSoft Enterprise PeopleTools
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openssl-3-livepatches-debuginfo
openssl-3-livepatches
openssl-3-livepatches-debugsource
openssl (Ubuntu package)
openssl (Red Hat package)
libopenssl-3-devel-64bit
libopenssl3-64bit
openssl-3-doc
libopenssl3-32bit
libopenssl-3-devel-32bit
libopenssl3-32bit-debuginfo
libopenssl3
libopenssl-3-devel
openssl-3-debugsource
openssl-3
openssl-3-debuginfo
libopenssl3-debuginfo
libopenssl3-64bit-debuginfo
openssl
openssl-devel
openssl-libs
openssl-perl
openssl-doc
openssl-debugsource
openssl-debuginfo
openssl-help
openssl (Debian package)
libopenssl-3-fips-provider
libopenssl-3-fips-provider-debuginfo
libopenssl-3-fips-provider-32bit-debuginfo
libopenssl-3-fips-provider-32bit
libopenssl-3-fips-provider-64bit
libopenssl-3-fips-provider-64bit-debuginfo
openssl3
edk2-ovmf
edk2-help
edk2-aarch64
edk2-devel
python3-edk2-devel
edk2-debugsource
edk2-debuginfo
edk2
Splunk Universal Forwarder
Oracle Communications Cloud Native Core Console
ExtremeCloud IQ Controller
ExtremeAnalytics for Site Engine
ExtremeControl for Site Engine
ExtremeCloud IQ Site Engine

How to mitigate CVE-2025-15467

Install updates from vendor's website.

OpenSSL - addressed in versions 3.0.19, 3.3.6, 3.4.4, 3.5.5, 3.6.1
SecurityCenter - addressed in versions SC202607.1, SC202607.2
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Cloud Pak System - update to 2.3.5.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
IBM OS Image for Red Hat Linux Systems - update to 5.0.2.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
FortiPortal - update to 7.4.9
LANTIME Operating System Firmware (LTOS) - update to 7.10.008
FortiNAC-F - addressed in versions 7.4.3, 7.6.6
IBM MQ - addressed in versions 9.1.0.34, 9.2.0.41, 9.3.0.37, 9.4.0.20
Splunk Universal Forwarder - addressed in versions 10.0.4, 10.2.1
IBM Security Verify Directory - update to 10.0.4.3 IF1
Integration Bus for z/OS - update to 10.1.0.7 PH71628
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 2
IBM App Connect Enterprise - addressed in versions 12.0.12.27, 13.0.8.0
AppDynamics NodeJS Agent - update to 25.12.1
openssl-3-livepatches-debuginfo - addressed in versions 0.4-150600.13.11.1, 0.4-150700.16.6.1
openssl-3-livepatches - addressed in versions 0.4-150600.13.11.1, 0.4-150700.16.6.1
openssl-3-livepatches-debugsource - addressed in versions 0.4-150600.13.11.1, 0.4-150700.16.6.1
Service Interconnect - update to 1
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.0.2n-1ubuntu5.13+esm3, 1.1.1f-1ubuntu2.24+esm2, 1.1.1-1ubuntu2.1~18.04.23+esm7, 3.0.2-0ubuntu1.21, 3.0.13-0ubuntu3.7, 3.5.3-1ubuntu3
openssl (Red Hat package) - addressed in versions 3.0.1-46.el9_0.7, 3.0.7-18.el9_2.3, 3.0.7-29.el9_4.2, 3.2.2-7.el9_6.2, 3.2.2-16.el10_0.6, 3.5.1-7.el9_7, 3.5.1-7.el10_1
libopenssl-3-devel-64bit - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-150600.5.42.1
libopenssl3-64bit - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-150600.5.42.1
openssl-3-doc - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-150600.5.42.1
libopenssl3-32bit - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1
libopenssl-3-devel-32bit - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-150600.5.42.1
libopenssl3-32bit-debuginfo - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1
libopenssl3 - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-slfo.1.1_8.1, 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1, 3.5.0-160000.5.1
libopenssl-3-devel - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-slfo.1.1_8.1, 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1, 3.5.0-160000.5.1
openssl-3-debugsource - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-slfo.1.1_8.1, 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1, 3.5.0-160000.5.1
openssl-3 - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-slfo.1.1_8.1, 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1, 3.5.0-160000.5.1
openssl-3-debuginfo - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-slfo.1.1_8.1, 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1, 3.5.0-160000.5.1
libopenssl3-debuginfo - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-slfo.1.1_8.1, 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1, 3.5.0-160000.5.1
libopenssl3-64bit-debuginfo - addressed in versions 3.0.8-150400.4.78.1, 3.0.8-150500.5.57.1, 3.1.4-150600.5.42.1
openssl - update to 3.0.12-17
openssl-devel - update to 3.0.12-17
openssl-libs - update to 3.0.12-17
openssl-perl - update to 3.0.12-17
openssl-doc - update to 3.0.12-17
openssl-debugsource - addressed in versions 3.0.12-24, 3.0.12-32
openssl-perl - addressed in versions 3.0.12-24, 3.0.12-32
openssl-libs - addressed in versions 3.0.12-24, 3.0.12-32
openssl-debuginfo - addressed in versions 3.0.12-24, 3.0.12-32
openssl-help - addressed in versions 3.0.12-24, 3.0.12-32
openssl - addressed in versions 3.0.12-24, 3.0.12-32
openssl-devel - addressed in versions 3.0.12-24, 3.0.12-32
openssl (Debian package) - addressed in versions 3.0.18-1~deb12u2, 3.5.4-1~deb13u2
libopenssl-3-fips-provider - addressed in versions 3.1.4-slfo.1.1_8.1, 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1, 3.5.0-160000.5.1
libopenssl-3-fips-provider-debuginfo - addressed in versions 3.1.4-slfo.1.1_8.1, 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1, 3.5.0-160000.5.1
libopenssl-3-fips-provider-32bit-debuginfo - addressed in versions 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1
libopenssl-3-fips-provider-32bit - addressed in versions 3.1.4-150600.5.42.1, 3.2.3-150700.5.24.1
libopenssl-3-fips-provider-64bit - update to 3.1.4-150600.5.42.1
libopenssl-3-fips-provider-64bit-debuginfo - update to 3.1.4-150600.5.42.1
openssl - addressed in versions 3.2.6-3.fc42, 3.5.4-2.fc43
openssl3 - update to 3.5.5-1.1.el8
NativeEdge Orchestrator - update to 4.2.0.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.64, 4.14.62, 4.15.62, 4.16.57, 4.17.49, 4.18.33, 4.19.24, 4.20.14
ExtremeCloud IQ Controller - update to 10.19.01
ExtremeAnalytics for Site Engine - update to 26.02.11
ExtremeCloud IQ Site Engine - update to 26.02.11
ExtremeControl for Site Engine - update to 26.02.11
edk2-ovmf - addressed in versions 202308-27, 202308-30, 202308-32
edk2-help - addressed in versions 202308-27, 202308-30, 202308-32
edk2-aarch64 - addressed in versions 202308-27, 202308-30, 202308-32
edk2-devel - addressed in versions 202308-27, 202308-30, 202308-32
python3-edk2-devel - addressed in versions 202308-27, 202308-30, 202308-32
edk2-debugsource - addressed in versions 202308-27, 202308-30, 202308-32
edk2-debuginfo - addressed in versions 202308-27, 202308-30, 202308-32
edk2 - addressed in versions 202308-27, 202308-30, 202308-32

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins