---
schema_version: '1.0'
id: security-20260705-bd7b52
url: https://osv.dev/vulnerability/DEBIAN-CVE-2025-9230
url_hash: bd7b5279c3bac78fc3963659e8178a5d603cde8da9e1a35a0e3e5967b40df958
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2025-9230
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2025-9230
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- openssl
- Debian
lang: en
published_at: '2025-09-30T14:15:41Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-05T15:35:57Z'
status: published
content_hash: 9e8b77e8cb2981e8eb42931b94b40814d24fa84396a74838aff5c093d476f86a
license_note: full
summary: 'Issue summary: An application trying to decrypt CMS messages encrypted using
  password based encryption can trigger an out-of-bounds read and write.  Impact summary:
  This out-of-bounds read may trigger a crash which leads to Denial of Service for
  an application. The out-of-bounds '
summary_source: rss
summary_en: 'Issue summary: An application trying to decrypt CMS messages encrypted
  using password based encryption can trigger an out-of-bounds read and write.  Impact
  summary: This out-of-bounds read may trigger a crash which leads to Denial of Service
  for an application. The out-of-bounds '
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2025-9230 — openssl
---

# DEBIAN-CVE-2025-9230 — openssl

## TL;DR
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds 

## Key Points
- cve / DEBIAN-CVE-2025-9230 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H / openssl / Debian

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
**Advisory:** DEBIAN-CVE-2025-9230

**Affected (your watchlist):**
- `Debian:openssl` 3.0.11-1~deb12u2 → no fixed version listed [rpi]

**Details:**
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code.  Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy.  The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2025-9230

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2025-9230_

## Source
元記事: [DEBIAN-CVE-2025-9230 — openssl](https://osv.dev/vulnerability/DEBIAN-CVE-2025-9230) — published 2025-09-30T14:15:41Z
