Resource exhaustion in OpenSSL - CVE-2025-66199
Published: January 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in CompressedCertificate. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected.
Servers that do not request client certificates are not vulnerable to client-initiated attacks.
Affected software
Debian Linux
SUSE Linux Micro
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
FreeBSD
Ubuntu
Fedora
SecurityCenter
Netezza Appliance
Virtualization Management Interface
IBM Cloud Pak System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM MQ
AppDynamics NodeJS Agent
LANTIME Operating System Firmware (LTOS)
openssl (Ubuntu package)
openssl (Debian package)
libopenssl3
libopenssl-3-fips-provider-debuginfo
openssl-3
openssl-3-debugsource
openssl-3-debuginfo
libopenssl-3-fips-provider
libopenssl-3-devel
libopenssl3-debuginfo
openssl (Red Hat package)
openssl
How to mitigate CVE-2025-66199
SecurityCenter - addressed in versions SC202607.1, SC202607.2
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Cloud Pak System - update to 2.3.5.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
LANTIME Operating System Firmware (LTOS) - update to 7.10.008
IBM MQ - addressed in versions 9.1.0.34, 9.2.0.41, 9.3.0.37, 9.4.0.20
AppDynamics NodeJS Agent - update to 25.12.1
Virtualization Management Interface - addressed in versions FW1060.62, FW1110.30
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.0.2n-1ubuntu5.13+esm3, 1.1.1f-1ubuntu2.24+esm2, 1.1.1-1ubuntu2.1~18.04.23+esm7, 3.0.2-0ubuntu1.21, 3.0.13-0ubuntu3.7, 3.5.3-1ubuntu3
openssl (Debian package) - addressed in versions 3.0.18-1~deb12u2, 3.5.4-1~deb13u2
libopenssl3 - update to 3.5.0-160000.5.1
libopenssl-3-fips-provider-debuginfo - update to 3.5.0-160000.5.1
openssl-3 - update to 3.5.0-160000.5.1
openssl-3-debugsource - update to 3.5.0-160000.5.1
openssl-3-debuginfo - update to 3.5.0-160000.5.1
libopenssl-3-fips-provider - update to 3.5.0-160000.5.1
libopenssl-3-devel - update to 3.5.0-160000.5.1
libopenssl3-debuginfo - update to 3.5.0-160000.5.1
openssl (Red Hat package) - addressed in versions 3.5.1-7.el9_7, 3.5.1-7.el10_1
openssl - update to 3.5.4-2.fc43
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Ubuntu update for openssl
- Fedora 43 update for openssl
- Ubuntu update for openssl
- Debian update for openssl
- Red Hat Enterprise Linux 10 update for openssl
- Red Hat Enterprise Linux 9 update for openssl
- SUSE update for openssl-3
- Meinberg LANTIME firmware update for third-party components
- Multiple vulnerabilities in IBM MQ
- Splunk AppDynamics NodeJS Agent update for third-party components
- FreeBSD update for OpenSSL
- Multiple vulnerabilities in IBM Netezza Appliance
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager
- Resource exhaustion in IBM Virtualization Management Interface
- Multiple vulnerabilities in Tenable Security Center
- Tenable Security Center on Enclave Security update for third-party components