---
schema_version: '1.0'
id: security-20260705-8bb6e3
url: https://osv.dev/vulnerability/DEBIAN-CVE-2025-4575
url_hash: 8bb6e3797af8d43dbdd29b355768abfdc6725e686c33fbefb441a4d112237771
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2025-4575
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2025-4575
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- openssl
- Debian
lang: en
published_at: '2025-05-22T14:16:07Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-05T15:35:57Z'
status: published
content_hash: cd72dc96b80d12700111ab986f227d8e56564632093d70811e9662a24ae7bcf7
license_note: full
summary: 'Issue summary: Use of -addreject option with the openssl x509 application
  adds a trusted use instead of a rejected use for a certificate.  Impact summary:
  If a user intends to make a trusted certificate rejected for a particular use it
  will be instead marked as trusted for that u'
summary_source: rss
summary_en: 'Issue summary: Use of -addreject option with the openssl x509 application
  adds a trusted use instead of a rejected use for a certificate.  Impact summary:
  If a user intends to make a trusted certificate rejected for a particular use it
  will be instead marked as trusted for that u'
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2025-4575 — openssl
---

# DEBIAN-CVE-2025-4575 — openssl

## TL;DR
Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate.  Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead marked as trusted for that u

## Key Points
- cve / DEBIAN-CVE-2025-4575 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L / openssl / Debian

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
**Advisory:** DEBIAN-CVE-2025-4575

**Affected (your watchlist):**
- `Debian:openssl` 3.0.11-1~deb12u2 → no fixed version listed [rpi]

**Details:**
Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate.  Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead marked as trusted for that use.  A copy & paste error during minor refactoring of the code introduced this issue in the OpenSSL 3.5 version. If, for example, a trusted CA certificate should be trusted only for the purpose of authenticating TLS servers but not for CMS signature verification and the CMS signature verification is intended to be marked as rejected with the -addreject option, the resulting CA certificate will be trusted for CMS signature verification purpose instead.  Only users which use the trusted certificate format who use the openssl x509 command line application to add rejected uses are affected by this issue. The issues affecting only the command line application are considered to be Low severity.  The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.  OpenSSL 3.4, 3.3, 3.2, 3.1, 3.0, 1.1.1 and 1.0.2 are also not affected by this issue.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2025-4575

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2025-4575_

## Source
元記事: [DEBIAN-CVE-2025-4575 — openssl](https://osv.dev/vulnerability/DEBIAN-CVE-2025-4575) — published 2025-05-22T14:16:07Z
