{"schema_version":"1.9.0","id":"CVE-2025-15467","published":"2026-01-27T16:01:19.922Z","modified":"2026-09-09T08:15:14.068600Z","related":["ALSA-2026:1472","ALSA-2026:1473","SUSE-SU-2026:0309-1","SUSE-SU-2026:0310-1","SUSE-SU-2026:0311-1","SUSE-SU-2026:0312-1","SUSE-SU-2026:20211-1","SUSE-SU-2026:20223-1","SUSE-SU-2026:20349-1","SUSE-SU-2026:20373-1","SUSE-SU-2026:20542-1","SUSE-SU-2026:20607-1","SUSE-SU-2026:21544-1","SUSE-SU-2026:22143-1","SUSE-SU-2026:2411-1","SUSE-SU-2026:2662-1","openSUSE-SU-2026:10237-1","openSUSE-SU-2026:20152-1"],"summary":"Stack buffer overflow in CMS (Auth)EnvelopedData parsing","details":"Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with\nmaliciously crafted AEAD parameters can trigger a stack buffer overflow.\n\nImpact summary: A stack buffer overflow may lead to a crash, causing Denial\nof Service, or potentially remote code execution.\n\nWhen parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as\nAES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is\ncopied into a fixed-size stack buffer without verifying that its length fits\nthe destination. An attacker can supply a crafted CMS message with an\noversized IV, causing a stack-based out-of-bounds write before any\nauthentication or tag verification occurs.\n\nApplications and services that parse untrusted CMS or PKCS#7 content using\nAEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.\nBecause the overflow occurs prior to authentication, no valid key material\nis required to trigger it. While exploitability to remote code execution\ndepends on platform and toolchain mitigations, the stack-based write\nprimitive represents a severe risk.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.\n\nOpenSSL 1.1.1 and 1.0.2 are not affected by this issue.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"89cd17a031e022211684eb7eb41190cf1910f9fa"},{"fixed":"a22063cd69a077cc68bb4c10e9f351f75899b194"},{"introduced":"a92271e03a8d0dee507b6f1e7f49512568b2c7ad"},{"fixed":"4601ff25acd6c2fe58a8bfe241e6c470e27b8074"},{"introduced":"98acb6b02839c609ef5b837794e08d906d965335"},{"fixed":"565bdcc41bbf89fcbaf962636469332689f0c9fd"},{"introduced":"636dfadc70ce26f2473870570bfd9ec352806b1d"},{"fixed":"67b5686b4419b4cb8caa502711c41815f5279751"},{"introduced":"7b371d80d959ec9ab4139d09d78e83c090de9779"},{"fixed":"c9a9e5b10105ad850b6e4d1122c645c67767c341"},{"fixed":"2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703"},{"fixed":"5f26d4202f5b89664c5c3f3c62086276026ba9a9"},{"fixed":"6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3"},{"fixed":"ce39170276daec87f55c39dad1f629b56344429e"},{"fixed":"d0071a0799f20cc8101730145349ed4487c268dc"}],"database_specific":{"cpe":"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.0.19"},{"introduced":"3.1.0"},{"fixed":"3.3.6"},{"introduced":"3.4.0"},{"fixed":"3.4.4"},{"introduced":"3.5.0"},{"fixed":"3.5.5"},{"introduced":"3.6.0"},{"fixed":"3.6.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.4-POST-CLANG-FORMAT-WEBKIT","3.0-POST-CLANG-FORMAT-WEBKIT","3.4-PRE-CLANG-FORMAT-WEBKIT","3.5-POST-CLANG-FORMAT-WEBKIT","3.0-PRE-CLANG-FORMAT-WEBKIT","3.5-PRE-CLANG-FORMAT-WEBKIT","3.6-POST-CLANG-FORMAT-WEBKIT","3.6-PRE-CLANG-FORMAT-WEBKIT","openssl-3.6.0","openssl-3.0.18","openssl-3.4.3","openssl-3.5.4","openssl-3.5.3","openssl-3.5.2","openssl-3.0.17","openssl-3.4.2","openssl-3.5.1","openssl-3.5.0","openssl-3.0.16","openssl-3.4.1","openssl-3.4.0","openssl-3.0.15","openssl-3.0.14","openssl-3.0.13","openssl-3.0.12","openssl-3.0.11","openssl-3.0.10","openssl-3.0.9","openssl-3.0.8","openssl-3.0.7","openssl-3.0.6","openssl-3.0.5","openssl-3.0.4","openssl-3.0.3","openssl-3.0.2","openssl-3.0.1","openssl-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15467.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"261110716343456066027997908770781220296","length":397},"id":"CVE-2025-15467-1e371f18","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3","target":{"file":"crypto/evp/evp_lib.c","function":"evp_cipher_get_asn1_aead_params"}},{"deprecated":false,"digest":{"line_hashes":["329585517079468733742312775788864029426","327536308535298630924771728884983816353","88199777040146306777862072605468896983","236713277121956468037986916213201116762","270753591454495127952041042908362536807","120586877600854545384530917415069442679","57068494517769352419947872617133408074"],"threshold":0.9},"id":"CVE-2025-15467-61300984","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e","target":{"file":"crypto/evp/evp_lib.c"}},{"deprecated":false,"digest":{"function_hash":"261110716343456066027997908770781220296","length":397},"id":"CVE-2025-15467-670a7c72","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc","target":{"file":"crypto/evp/evp_lib.c","function":"evp_cipher_get_asn1_aead_params"}},{"deprecated":false,"digest":{"line_hashes":["329585517079468733742312775788864029426","327536308535298630924771728884983816353","88199777040146306777862072605468896983","236713277121956468037986916213201116762","270753591454495127952041042908362536807","120586877600854545384530917415069442679","57068494517769352419947872617133408074"],"threshold":0.9},"id":"CVE-2025-15467-7419a4ad","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc","target":{"file":"crypto/evp/evp_lib.c"}},{"deprecated":false,"digest":{"function_hash":"261110716343456066027997908770781220296","length":397},"id":"CVE-2025-15467-8bf47941","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9","target":{"file":"crypto/evp/evp_lib.c","function":"evp_cipher_get_asn1_aead_params"}},{"deprecated":false,"digest":{"line_hashes":["329585517079468733742312775788864029426","327536308535298630924771728884983816353","88199777040146306777862072605468896983","236713277121956468037986916213201116762","270753591454495127952041042908362536807","120586877600854545384530917415069442679","57068494517769352419947872617133408074"],"threshold":0.9},"id":"CVE-2025-15467-94831191","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3","target":{"file":"crypto/evp/evp_lib.c"}},{"deprecated":false,"digest":{"line_hashes":["329585517079468733742312775788864029426","327536308535298630924771728884983816353","88199777040146306777862072605468896983","236713277121956468037986916213201116762","270753591454495127952041042908362536807","120586877600854545384530917415069442679","57068494517769352419947872617133408074"],"threshold":0.9},"id":"CVE-2025-15467-adc28bb0","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9","target":{"file":"crypto/evp/evp_lib.c"}},{"deprecated":false,"digest":{"line_hashes":["329585517079468733742312775788864029426","327536308535298630924771728884983816353","88199777040146306777862072605468896983","236713277121956468037986916213201116762","270753591454495127952041042908362536807","120586877600854545384530917415069442679","57068494517769352419947872617133408074"],"threshold":0.9},"id":"CVE-2025-15467-bceb1912","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703","target":{"file":"crypto/evp/evp_lib.c"}},{"deprecated":false,"digest":{"function_hash":"261110716343456066027997908770781220296","length":397},"id":"CVE-2025-15467-f075c03c","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703","target":{"file":"crypto/evp/evp_lib.c","function":"evp_cipher_get_asn1_aead_params"}},{"deprecated":false,"digest":{"function_hash":"261110716343456066027997908770781220296","length":397},"id":"CVE-2025-15467-f8e81b92","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e","target":{"file":"crypto/evp/evp_lib.c","function":"evp_cipher_get_asn1_aead_params"}}],"vanir_signatures_modified":"2026-09-09T08:15:14Z"}}],"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/01/27/10"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/02/25/6"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-434797.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-734552.html"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:1472"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:1473"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:1496"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:1503"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:1519"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:1594"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:1733"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:1736"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2072"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2077"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2485"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2563"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2633"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2659"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2671"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2844"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2974"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2995"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3228"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3415"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3461"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4419"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4943"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6481"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:7261"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-15467"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15467.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15467"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260127.txt"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2430376"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc"},{"type":"EVIDENCE","url":"https://github.com/guiimoraes/CVE-2025-15467"}],"database_specific":{"cna_assigner":"openssl","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15467.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}