Junglewise Threat Intelligence

CVE-2025-68160: OpenSSL heap overflow in BIO_f_linebuffer

CVE-2025-68160 · Severity: medium · CVSS 4.7 · Published 2026-01-27

Technologies: OpenSSL. Vendors: OpenSSL.

Executive brief

OpenSSL is a widely used security library that provides encryption and secure communication for applications. A vulnerability in its line-buffering component could allow an attacker to crash an application, leading to a denial of service. This issue primarily affects third-party applications that manually enable specific line-buffering settings and is not active in standard web traffic (TLS/SSL) by default.

Technical details

A heap-based out-of-bounds write exists in the OpenSSL BIO_f_linebuffer filter. The vulnerability is triggered when large, newline-free data is written into a BIO chain where the line-buffering filter is used and the subsequent BIO performs short writes. In this scenario, unwritten data is unconditionally copied to an internal buffer (ctx->obuf) without sufficient bounds checking. An attacker who can influence the data processed by this filter could cause memory corruption, typically resulting in a Denial of Service (DoS). The issue is considered low severity because BIO_f_linebuffer is not used by default in TLS/SSL paths and is rarely exposed to untrusted input. Patches have been released for all major OpenSSL branches.

Affected products

  • OpenSSL OpenSSL 3.6.0 to 3.6.1, 3.5.0 to 3.5.5, 3.4.0 to 3.4.4, 3.3.0 to 3.3.6, 3.0.0 to 3.0.19, 1.1.1 to 1.1.1ze, 1.0.2 to 1.0.2zn

Timeline

  • 2026-01-27: advisory: OpenSSL Security Advisory published
  • 2026-01-27: disclosed
  • 2026-01-26: patched: Fixes committed to OpenSSL repository

References

Related threats