Security update for openssl-3-livepatches
This update for openssl-3-livepatches fixes the following issues: - CVE-2025-11187: Fixed improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Fixed stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: Fixed NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2025-9230: Fixed out-of-bounds read & write in RFC 3211 KEK Unwrap (bsc#1250410).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for openssl-3-livepatches fixes the following issues: - CVE-2025-11187: Fixed improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Fixed stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: Fixed NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2025-9230: Fixed out-of-bounds read & write in RFC 3211 KEK Unwrap (bsc#1250410).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1250410
- https://bugzilla.suse.com/1256876
- https://bugzilla.suse.com/1256878
- https://bugzilla.suse.com/1256880
- https://www.suse.com/security/cve/CVE-2025-11187
- https://www.suse.com/security/cve/CVE-2025-15467
- https://www.suse.com/security/cve/CVE-2025-15468
- https://www.suse.com/security/cve/CVE-2025-9230
- https://www.suse.com/support/update/announcement/2026/suse-su-202620607-1/