FlawAtlas
Search the atlas
USN-7786-1 Not scored

openssl, openssl1.0 vulnerabilities

Stanislav Fort discovered that OpenSSL incorrectly handled memory when trying to decrypt CMS messages encrypted with password-based encryption. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2025-9230) Stanislav Fort discovered that OpenSSL had a timing side-channel in SM2 signature computations on ARM platforms. A remote attacker could possibly use this issue to recover private data. This issue only affected Ubuntu 25.04. (CVE-2025-9231) Stanislav Fort discovered that OpenSSL incorrectly handled memory during HTTP requests when "no_proxy" environment variable is set. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.04. (CVE-2025-9232)

Exploit probability Not scored
Published September 30, 2025
Required by Not available
Last source change June 25, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:22.04:LTS openssl

21 explicit affected versions

Ubuntu:24.04:LTS openssl

11 explicit affected versions

Ubuntu:Pro:14.04:LTS openssl

38 explicit affected versions

Ubuntu:Pro:16.04:LTS openssl

36 explicit affected versions

Ubuntu:Pro:18.04:LTS openssl

32 explicit affected versions

Ubuntu:Pro:18.04:LTS openssl1.0

18 explicit affected versions

Ubuntu:Pro:20.04:LTS openssl

26 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-7786-1

Stanislav Fort discovered that OpenSSL incorrectly handled memory when trying to decrypt CMS messages encrypted with password-based encryption. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2025-9230) Stanislav Fort discovered that OpenSSL had a timing side-channel in SM2 signature computations on ARM platforms. A remote attacker could possibly use this issue to recover private data. This issue only affected Ubuntu 25.04. (CVE-2025-9231) Stanislav Fort discovered that OpenSSL incorrectly handled memory during HTTP requests when "no_proxy" environment variable is set. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.04. (CVE-2025-9232)

View original source

05 / REFERENCES

Further evidence