Numeric Truncation Error in OpenSSL - CVE-2025-15469
Published: January 27, 2026
Vulnerability identifier: #VU122078
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-15469
CWE-ID: CWE-197
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to "openssl dgst" one-shot codepath silently truncates inputs larger than 16MB. A remote attacker can spoof contents of the signed message.
Note, the issue affects only the command-line tool behavior.
Affected software
OpenSSL
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Micro
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
FreeBSD
Ubuntu
Basesystem Module
Web and Scripting Module
Fedora
SecurityCenter
Netezza Appliance
NativeEdge Orchestrator
IBM Cloud Pak System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM MQ
openssl (Ubuntu package)
openssl (Debian package)
openssl
libopenssl-devel
libopenssl-fips-provider
libopenssl3-32bit-debuginfo
openssl-3
libopenssl-3-devel
libopenssl-3-fips-provider-debuginfo
openssl-3-debuginfo
libopenssl-3-fips-provider
libopenssl3
openssl-3-debugsource
libopenssl3-debuginfo
libopenssl-3-fips-provider-32bit
libopenssl3-32bit
libopenssl-3-fips-provider-32bit-debuginfo
openssl (Red Hat package)
nodejs24-devel
npm24
nodejs24-debugsource
nodejs24
nodejs24-docs
nodejs24-debuginfo
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Micro
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
FreeBSD
Ubuntu
Basesystem Module
Web and Scripting Module
Fedora
SecurityCenter
Netezza Appliance
NativeEdge Orchestrator
IBM Cloud Pak System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM MQ
openssl (Ubuntu package)
openssl (Debian package)
openssl
libopenssl-devel
libopenssl-fips-provider
libopenssl3-32bit-debuginfo
openssl-3
libopenssl-3-devel
libopenssl-3-fips-provider-debuginfo
openssl-3-debuginfo
libopenssl-3-fips-provider
libopenssl3
openssl-3-debugsource
libopenssl3-debuginfo
libopenssl-3-fips-provider-32bit
libopenssl3-32bit
libopenssl-3-fips-provider-32bit-debuginfo
openssl (Red Hat package)
nodejs24-devel
npm24
nodejs24-debugsource
nodejs24
nodejs24-docs
nodejs24-debuginfo
How to mitigate CVE-2025-15469
Install updates from vendor's website.
OpenSSL - addressed in versions 3.5.5, 3.6.1
SecurityCenter - addressed in versions SC202607.1, SC202607.2
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Cloud Pak System - update to 2.3.5.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
IBM MQ - addressed in versions 9.1.0.34, 9.2.0.41, 9.3.0.37, 9.4.0.20
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.0.2n-1ubuntu5.13+esm3, 1.1.1f-1ubuntu2.24+esm2, 1.1.1-1ubuntu2.1~18.04.23+esm7, 3.0.2-0ubuntu1.21, 3.0.13-0ubuntu3.7, 3.5.3-1ubuntu3
openssl (Debian package) - addressed in versions 3.0.18-1~deb12u2, 3.5.4-1~deb13u2
openssl - update to 3.5.0-150700.3.4.1
libopenssl-devel - update to 3.5.0-150700.3.4.1
libopenssl-fips-provider - update to 3.5.0-150700.3.4.1
libopenssl3-32bit-debuginfo - update to 3.5.0-150700.5.45.2
openssl-3 - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl-3-devel - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl-3-fips-provider-debuginfo - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
openssl-3-debuginfo - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl-3-fips-provider - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl3 - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
openssl-3-debugsource - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl3-debuginfo - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl-3-fips-provider-32bit - update to 3.5.0-150700.5.45.2
libopenssl3-32bit - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-32bit-debuginfo - update to 3.5.0-150700.5.45.2
openssl (Red Hat package) - addressed in versions 3.5.1-7.el9_7, 3.5.1-7.el10_1
openssl - update to 3.5.4-2.fc43
NativeEdge Orchestrator - update to 4.2.0.0
nodejs24-devel - update to 24.18.1-150700.15.18.1
npm24 - update to 24.18.1-150700.15.18.1
nodejs24-debugsource - update to 24.18.1-150700.15.18.1
nodejs24 - update to 24.18.1-150700.15.18.1
nodejs24-docs - update to 24.18.1-150700.15.18.1
nodejs24-debuginfo - update to 24.18.1-150700.15.18.1
SecurityCenter - addressed in versions SC202607.1, SC202607.2
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Cloud Pak System - update to 2.3.5.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
IBM MQ - addressed in versions 9.1.0.34, 9.2.0.41, 9.3.0.37, 9.4.0.20
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.0.2n-1ubuntu5.13+esm3, 1.1.1f-1ubuntu2.24+esm2, 1.1.1-1ubuntu2.1~18.04.23+esm7, 3.0.2-0ubuntu1.21, 3.0.13-0ubuntu3.7, 3.5.3-1ubuntu3
openssl (Debian package) - addressed in versions 3.0.18-1~deb12u2, 3.5.4-1~deb13u2
openssl - update to 3.5.0-150700.3.4.1
libopenssl-devel - update to 3.5.0-150700.3.4.1
libopenssl-fips-provider - update to 3.5.0-150700.3.4.1
libopenssl3-32bit-debuginfo - update to 3.5.0-150700.5.45.2
openssl-3 - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl-3-devel - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl-3-fips-provider-debuginfo - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
openssl-3-debuginfo - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl-3-fips-provider - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl3 - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
openssl-3-debugsource - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl3-debuginfo - addressed in versions 3.5.0-150700.5.45.2, 3.5.0-160000.5.1
libopenssl-3-fips-provider-32bit - update to 3.5.0-150700.5.45.2
libopenssl3-32bit - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-32bit-debuginfo - update to 3.5.0-150700.5.45.2
openssl (Red Hat package) - addressed in versions 3.5.1-7.el9_7, 3.5.1-7.el10_1
openssl - update to 3.5.4-2.fc43
NativeEdge Orchestrator - update to 4.2.0.0
nodejs24-devel - update to 24.18.1-150700.15.18.1
npm24 - update to 24.18.1-150700.15.18.1
nodejs24-debugsource - update to 24.18.1-150700.15.18.1
nodejs24 - update to 24.18.1-150700.15.18.1
nodejs24-docs - update to 24.18.1-150700.15.18.1
nodejs24-debuginfo - update to 24.18.1-150700.15.18.1
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Ubuntu update for openssl
- Fedora 43 update for openssl
- Ubuntu update for openssl
- Debian update for openssl
- Red Hat Enterprise Linux 10 update for openssl
- Red Hat Enterprise Linux 9 update for openssl
- SUSE update for openssl-3
- Multiple vulnerabilities in IBM MQ
- FreeBSD update for OpenSSL
- Multiple vulnerabilities in IBM Netezza Appliance
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in Tenable Security Center
- Tenable Security Center on Enclave Security update for third-party components
- Multiple vulnerabilities in Dell NativeEdge Orchestrator
- SUSE update for openssl, openssl-3