#VU122082 Out-of-bounds write in OpenSSL - CVE-2025-69419
Published: January 27, 2026
OpenSSL
OpenSSL Software Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error within the PKCS12_get_friendlyname() function when parsing PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point. A remote attacker can pass a specially crafted PKCS#12 file to the application, trigger an out-of-bounds write and perform a denial of service attack.