Junglewise Threat Intelligence

CVE-2025-9230: OpenSSL out-of-bounds read and write in CMS password-based encryption

CVE-2025-9230 · Severity: high · CVSS 7.5 · Published 2025-09-30

Technologies: OpenSSL. Vendors: OpenSSL.

Executive brief

OpenSSL, a widely used security library for encrypting internet communications, contains a flaw in how it handles certain types of password-protected messages. An attacker could send a specially crafted message that causes an application using OpenSSL to crash or potentially execute unauthorized code. While the impact is severe, this specific type of encryption is rarely used in modern systems, reducing the overall likelihood of a successful attack.

Technical details

An out-of-bounds read and write vulnerability exists in the OpenSSL CMS implementation, specifically within the kek_unwrap_key() function in crypto/cms/cms_pwri.c. The root cause is an incorrect length check for the unwrapped key size, which is off by 8 bytes. This allows an attacker to trigger an overread of up to 8 bytes and an overwrite of up to 4 bytes when the application attempts to decrypt a CMS message using password-based encryption (PWRI). Exploitation can lead to a denial-of-service (crash) or potentially remote code execution due to memory corruption. The FIPS modules are not affected as the CMS implementation resides outside the FIPS boundary. Patches have been committed to the OpenSSL repository.

Affected products

  • OpenSSL OpenSSL 3.0, 3.1, 3.2, 3.3, 3.4, 3.5

Timeline

  • 2025-09-30: disclosed
  • 2025-09-30: advisory
  • 2025-09-30: patched: Patches committed to OpenSSL GitHub repository

References

Related threats