FlawAtlas
Search the atlas
UBUNTU-CVE-2025-9230 High

UBUNTU-CVE-2025-9230

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

Exploit probability Not scored
Published September 30, 2025
Required by Not available
Last source change May 20, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:22.04:LTS openssl

21 explicit affected versions

Ubuntu:24.04:LTS openssl

11 explicit affected versions

Ubuntu:25.10 openssl

3 explicit affected versions

Ubuntu:26.04:LTS openssl
Ubuntu:Pro:14.04:LTS openssl

38 explicit affected versions

Ubuntu:Pro:16.04:LTS nodejs

12 explicit affected versions

Ubuntu:Pro:16.04:LTS openssl

36 explicit affected versions

Ubuntu:Pro:18.04:LTS nodejs

15 explicit affected versions

Ubuntu:Pro:18.04:LTS openssl

32 explicit affected versions

Ubuntu:Pro:18.04:LTS openssl1.0

18 explicit affected versions

Ubuntu:Pro:20.04:LTS openssl

26 explicit affected versions

Ubuntu:Pro:22.04:LTS nodejs

12 explicit affected versions

Ubuntu:Pro:FIPS-preview:22.04:LTS openssl

2 explicit affected versions

Ubuntu:Pro:FIPS-preview:22.04:LTS openssl-fips

1 explicit affected versions

Ubuntu:Pro:FIPS-updates:18.04:LTS openssl

18 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS openssl

13 explicit affected versions

Ubuntu:Pro:FIPS-updates:22.04:LTS openssl

8 explicit affected versions

Ubuntu:Pro:FIPS-updates:22.04:LTS openssl-fips

2 explicit affected versions

Ubuntu:Pro:FIPS-updates:24.04:LTS openssl-fips

1 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS openssl

7 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS openssl

16 explicit affected versions

Ubuntu:Pro:FIPS:18.04:LTS openssl

2 explicit affected versions

Ubuntu:Pro:FIPS:20.04:LTS openssl

2 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2025-9230

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

View original source

05 / REFERENCES

Further evidence