OpenSSL Vulnerabilities in Versions 3.5.4, 3.4.3, 3.3.5, 3.2.6, 3.0.18, 1.0.2zm, and 1.1.1zd
Summary
Hide ▲
Show ▼
The OpenSSL Project has released updates to fix three vulnerabilities in multiple versions of the OpenSSL library. The vulnerabilities, tracked as CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232, allow for private key recovery, arbitrary code execution, and denial-of-service (DoS) attacks. The most severe flaw, CVE-2025-9231, affects the SM2 algorithm implementation on 64-bit ARM platforms, potentially enabling attackers to recover private keys and decrypt encrypted traffic or conduct man-in-the-middle (MitM) attacks. The other two vulnerabilities, CVE-2025-9230 and CVE-2025-9232, have moderate and low severity ratings, respectively. The vulnerabilities were discovered in versions 3.5.4, 3.4.3, 3.3.5, 3.2.6, 3.0.18, 1.0.2zm, and 1.1.1zd of the OpenSSL library. The updates are available for immediate deployment to mitigate the risks associated with these vulnerabilities.
Timeline
-
01.10.2025 16:59 1 articles · 9h ago
OpenSSL Releases Patches for Three Vulnerabilities in Multiple Versions
The OpenSSL Project has released updates for versions 3.5.4, 3.4.3, 3.3.5, 3.2.6, 3.0.18, 1.0.2zm, and 1.1.1zd to address three vulnerabilities. CVE-2025-9231 allows private key recovery on 64-bit ARM platforms using the SM2 algorithm, potentially enabling decryption of encrypted traffic and MitM attacks. CVE-2025-9230 is an out-of-bounds read/write issue that can lead to arbitrary code execution or DoS attacks. CVE-2025-9232 is a low-severity vulnerability that can cause crashes resulting in DoS conditions. These updates are essential for mitigating the risks associated with these vulnerabilities.
Show sources
- OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks — www.securityweek.com — 01.10.2025 16:59
Information Snippets
-
The OpenSSL Project has released updates for versions 3.5.4, 3.4.3, 3.3.5, 3.2.6, 3.0.18, 1.0.2zm, and 1.1.1zd to address three vulnerabilities.
First reported: 01.10.2025 16:591 source, 1 articleShow sources
- OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks — www.securityweek.com — 01.10.2025 16:59
-
CVE-2025-9231 allows private key recovery on 64-bit ARM platforms using the SM2 algorithm.
First reported: 01.10.2025 16:591 source, 1 articleShow sources
- OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks — www.securityweek.com — 01.10.2025 16:59
-
CVE-2025-9230 is an out-of-bounds read/write issue that can lead to arbitrary code execution or DoS attacks.
First reported: 01.10.2025 16:591 source, 1 articleShow sources
- OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks — www.securityweek.com — 01.10.2025 16:59
-
CVE-2025-9232 is a low-severity vulnerability that can cause a crash, resulting in a DoS condition.
First reported: 01.10.2025 16:591 source, 1 articleShow sources
- OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks — www.securityweek.com — 01.10.2025 16:59
-
OpenSSL developers note that the SM2 algorithm vulnerability is not relevant in most TLS contexts but can be exploited in custom provider contexts.
First reported: 01.10.2025 16:591 source, 1 articleShow sources
- OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks — www.securityweek.com — 01.10.2025 16:59
-
The probability of exploiting CVE-2025-9230 is low, but the consequences could be severe.
First reported: 01.10.2025 16:591 source, 1 articleShow sources
- OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks — www.securityweek.com — 01.10.2025 16:59
-
Only three other issues have been resolved in 2025, with one having a high severity rating.
First reported: 01.10.2025 16:591 source, 1 articleShow sources
- OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks — www.securityweek.com — 01.10.2025 16:59