CVE-2025-4575

Published May 22, 2025

Last updated 9 months ago

Overview

Description
Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead marked as trusted for that use. A copy & paste error during minor refactoring of the code introduced this issue in the OpenSSL 3.5 version. If, for example, a trusted CA certificate should be trusted only for the purpose of authenticating TLS servers but not for CMS signature verification and the CMS signature verification is intended to be marked as rejected with the -addreject option, the resulting CA certificate will be trusted for CMS signature verification purpose instead. Only users which use the trusted certificate format who use the openssl x509 command line application to add rejected uses are affected by this issue. The issues affecting only the command line application are considered to be Low severity. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 3.4, 3.3, 3.2, 3.1, 3.0, 1.1.1 and 1.0.2 are also not affected by this issue.
Source
openssl-security@openssl.org
NVD status
Analyzed
Products
openssl

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
2.5
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Severity
MEDIUM

Weaknesses

openssl-security@openssl.org
CWE-295

Social media

Hype score
Not currently trending
  1. いま知るべき影響範囲と対策をやさしく整理。安心の解説です! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    6 Apr 2026

    92 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 今知るべき影響範囲と安全な対策をわかりやすく丁寧に解説します OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    6 Apr 2026

    136 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 影響範囲から実践的な対策まで、要点をわかりやすく解説します。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    4 Apr 2026

    182 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 最新の脆弱性をやさしく解説。影響範囲と対策を要点で確認しよう OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    2 Apr 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    21 Mar 2026

    88 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    17 Mar 2026

    133 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    15 Mar 2026

    179 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    11 Mar 2026

    111 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    7 Mar 2026

    127 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    24 Feb 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    13 Feb 2026

    51 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    18 Jan 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    12 Jan 2026

    61 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  14. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    11 Jan 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    22 Dec 2025

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    22 Dec 2025

    58 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    13 Dec 2025

    36 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  18. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    12 Dec 2025

    37 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 【アーカイブ】 【アーカイブ】 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    3 Dec 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 【アーカイブ】 OpenSSL 3.5の脆弱性と対策を詳解!配慮が必要です。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    18 Nov 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 【アーカイブ】 OpenSSL 3.5の脆弱性を解説!影響と対策は? OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    17 Nov 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 【アーカイブ】 OpenSSLの最新脆弱性について詳しく解説!対策必見! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #cybernote #ブログ仲間と繋がりたい #Webライタ

    @CyberNote_media

    17 Nov 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 【アーカイブ】 OpenSSL 3.5の重大脆弱性。影響と対策を詳しく解説。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #cybernote #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    15 Nov 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 【アーカイブ】 OpenSSLの最新脆弱性情報をわかりやすく解説! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    14 Nov 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 【アーカイブ】 OpenSSLの新たな脆弱性について知識を深めよう! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    13 Nov 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 【アーカイブ】 OpenSSL脆弱性の影響と対策を徹底解説します! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    10 Nov 2025

    28 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 【アーカイブ】 OpenSSLの脆弱性を徹底解説!対策法も紹介します。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    7 Nov 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 【アーカイブ】 重要なセキュリティ情報!脆弱性の詳細と対策を解説します。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #

    @CyberNote_media

    3 Nov 2025

    38 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 【アーカイブ】 OpenSSL 3.5の脆弱性詳細と対策を解説します! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9NNV #cybernote #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    2 Nov 2025

    30 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 【アーカイブ】 OpenSSL新脆弱性の影響と対策を簡潔解説! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    1 Nov 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. 【アーカイブ】 OpenSSLの脆弱性を知り、安全対策を今すぐチェック! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #cybernote #ブログ仲間と繋がりたい #Webライタ

    @CyberNote_media

    22 Oct 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 【アーカイブ】 OpenSSL最新脆弱性の詳細と対策を解説!安全確保に必読です。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #We

    @CyberNote_media

    11 Oct 2025

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 【アーカイブ】 重要なセキュリティ情報を詳しく解説!対策必見です。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #cybernote #ブログ仲間と繋がりたい #Webライ

    @CyberNote_media

    8 Oct 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 【アーカイブ】 OpenSSL新バージョンの脆弱性と対策を詳しく解説! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    6 Oct 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. 【アーカイブ】 OpenSSLの脆弱性と対策を詳しく解説!必読です。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #cybernote #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    6 Oct 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 【アーカイブ】 OpenSSL脆弱性の影響範囲と対策を詳しく解説!必見です。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #cybernote #ブログ仲間と繋がりたい #Webラ

    @Teeeda_worker

    5 Oct 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 【アーカイブ】 最新のOpenSSL脆弱性の詳細と対策法を解説! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    26 Sept 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. 【アーカイブ】 OpenSSL 3.5の新たな脆弱性に迫る!対策必見。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    22 Sept 2025

    43 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. 【アーカイブ】 OpenSSLの脆弱性とその対策を詳しく解説します! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    22 Sept 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. 【アーカイブ】 OpenSSLの脆弱性を詳しく解説!対策法も紹介。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #cybernote #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    21 Sept 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. 【アーカイブ】 OpenSSL 3.5の脆弱性を解説!影響と対策を紹介します。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #Webライタ

    @CyberNote_media

    20 Sept 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. 【アーカイブ】 OpenSSL 3.5の脆弱性を徹底解説!影響と対策方法を紹介します。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #cybernote #ブログ仲間と繋がりたい #W

    @CyberNote_media

    20 Sept 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 【アーカイブ】 OpenSSLの脆弱性の詳細と対策を簡単に解説します! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    18 Sept 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. 【アーカイブ】 OpenSSL 3.5の脆弱性とその対策を詳解!安全対策を確認しよう。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #W

    @CyberNote_media

    15 Sept 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. 【アーカイブ】 OpenSSL 3.5の脆弱性を徹底解説!対策も詳しく紹介します。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9fYn #cybernote #ブログ仲間と繋がりたい #Webラ

    @Teeeda_worker

    14 Sept 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 【アーカイブ】 OpenSSL脆弱性の影響と対策を詳しく解説。必見! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9NNV #cybernote #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    8 Sept 2025

    22 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  47. 【アーカイブ】 OpenSSLの新たな脆弱性とその対策を詳しく解説! OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKhP7m #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    7 Sept 2025

    33 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 【アーカイブ】 OpenSSLの新たな脆弱性を解説!影響と対策とは? OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9NNV #cybernote #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    6 Sept 2025

    42 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  49. 【アーカイブ】 OpenSSLの脆弱性を徹底解説!対策もご紹介。 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/2XaenM9NNV #cybernote #ブログ仲間と繋がりたい #Webライター

    @Teeeda_worker

    4 Sept 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 【アーカイブ】 OpenSSL 3.5の脆弱性を徹底解説!対策法も紹介 OpenSSL 3.5の脆弱性「CVE-2025-4575」とは?影響範囲や対策をわかりやすく解説 https://t.co/mq3XiKimWU #cybernote #ブログ仲間と繋がりたい #Webライター

    @CyberNote_media

    1 Sept 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

  1. Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key(). Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker. The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen. Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds. The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator. The FIPS modules are not affected by this issue.CVE-2026-9076
  2. Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour. In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation. X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity. The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.CVE-2026-7383
  3. Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers. AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully. In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value. When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key. AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2. No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.CVE-2026-45446
  4. Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality. If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message. OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex(). The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not. Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV. If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext. The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair. The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected. Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable. The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.CVE-2026-45445