Resource exhaustion in OpenSSL - CVE-2025-66199

 

Resource exhaustion in OpenSSL - CVE-2025-66199

Published: January 27, 2026


Vulnerability identifier: #VU122079
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66199
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in CompressedCertificate. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.

This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. 

Servers that do not request client certificates are not vulnerable to client-initiated attacks.


Affected software

OpenSSL
Debian Linux
SUSE Linux Micro
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
FreeBSD
Ubuntu
Fedora
SecurityCenter
Netezza Appliance
Virtualization Management Interface
IBM Cloud Pak System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM MQ
AppDynamics NodeJS Agent
LANTIME Operating System Firmware (LTOS)
openssl (Ubuntu package)
openssl (Debian package)
libopenssl3
libopenssl-3-fips-provider-debuginfo
openssl-3
openssl-3-debugsource
openssl-3-debuginfo
libopenssl-3-fips-provider
libopenssl-3-devel
libopenssl3-debuginfo
openssl (Red Hat package)
openssl

How to mitigate CVE-2025-66199

Install updates from vendor's website.

OpenSSL - addressed in versions 3.3.6, 3.4.4, 3.5.5, 3.6.1
SecurityCenter - addressed in versions SC202607.1, SC202607.2
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Cloud Pak System - update to 2.3.5.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
LANTIME Operating System Firmware (LTOS) - update to 7.10.008
IBM MQ - addressed in versions 9.1.0.34, 9.2.0.41, 9.3.0.37, 9.4.0.20
AppDynamics NodeJS Agent - update to 25.12.1
Virtualization Management Interface - addressed in versions FW1060.62, FW1110.30
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.0.2n-1ubuntu5.13+esm3, 1.1.1f-1ubuntu2.24+esm2, 1.1.1-1ubuntu2.1~18.04.23+esm7, 3.0.2-0ubuntu1.21, 3.0.13-0ubuntu3.7, 3.5.3-1ubuntu3
openssl (Debian package) - addressed in versions 3.0.18-1~deb12u2, 3.5.4-1~deb13u2
libopenssl3 - update to 3.5.0-160000.5.1
libopenssl-3-fips-provider-debuginfo - update to 3.5.0-160000.5.1
openssl-3 - update to 3.5.0-160000.5.1
openssl-3-debugsource - update to 3.5.0-160000.5.1
openssl-3-debuginfo - update to 3.5.0-160000.5.1
libopenssl-3-fips-provider - update to 3.5.0-160000.5.1
libopenssl-3-devel - update to 3.5.0-160000.5.1
libopenssl3-debuginfo - update to 3.5.0-160000.5.1
openssl (Red Hat package) - addressed in versions 3.5.1-7.el9_7, 3.5.1-7.el10_1
openssl - update to 3.5.4-2.fc43

External References

Related Security Bulletins