← Vulnerability feed

Vulnerability record · CVE-2025-15467 · published 27 January 2026

CVE-2025-15467: OpenSSL CMS AEAD IV stack buffer overflow

OOpenssl · Openssl

OpenSSL 3.0 through 3.6 copies the AEAD initialization vector from CMS (Auth)EnvelopedData ASN.1 parameters into a fixed-size stack buffer without checking its length, so an oversized IV causes a stack out-of-bounds write. The write happens before any authentication or tag verification, so no valid key material is needed to trigger it. Applications parsing untrusted CMS or PKCS#7 content with AEAD ciphers such as AES-GCM (for example S/MIME) are exposed.

8.8 CVSS 3.1 High EPSS 52% · top 1.1% CWE-787 · Out-of-bounds writeCWE-120 · Classic buffer overflow
8.8CVSS 3.1 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
40References, 1 tagged exploit
7 Sep 2026Last modified by NVD

Description

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 8.8 with a pre-authentication stack write and very high EPSS, though no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

OpenSSL 3.0 through 3.6 copies the AEAD initialization vector from CMS (Auth)EnvelopedData ASN.1 parameters into a fixed-size stack buffer without checking its length, so an oversized IV causes a stack out-of-bounds write. The write happens before any authentication or tag verification, so no valid key material is needed to trigger it. Applications parsing untrusted CMS or PKCS#7 content with AEAD ciphers such as AES-GCM (for example S/MIME) are exposed.

Impact

An attacker can crash the parsing process, causing denial of service, and the stack write primitive may allow remote code execution depending on platform and toolchain mitigations.

Attack surface

Reached remotely by delivering a crafted CMS or PKCS#7 message to a service or application that parses untrusted content with AEAD ciphers; the CVSS vector indicates no privileges are required but user interaction is needed. No valid key material is required because the overflow occurs before authentication.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is high at roughly 0.48 probability (98.8th percentile), and the references include only patches, a vendor advisory and mailing list posts.

What to do

  • Upgrade OpenSSL to a release containing the fixes referenced by the five patch commits and the vendor advisory; 1.1.1 and 1.0.2 are not affected.
  • Apply distribution errata (for example the listed Red Hat RHSA advisories) or vendor-supplied OpenSSL updates on affected hosts.
  • Where immediate patching is not possible, avoid parsing untrusted CMS/PKCS#7 (Auth)EnvelopedData with AEAD ciphers, or restrict such parsing to trusted sources.
  • Inventory applications and services that process S/MIME or CMS content with AES-GCM to confirm they link an affected OpenSSL 3.x version.
  • Note that FIPS module versions 3.0 through 3.6 are not affected because the CMS implementation sits outside the FIPS module boundary.

Detection

  • Monitor for crashes or abnormal termination in processes that parse CMS/PKCS#7 or S/MIME messages.
  • Inspect CMS (Auth)EnvelopedData inputs for AEAD parameters carrying abnormally large IV values.
  • Track OpenSSL library versions across hosts and flag any still on affected 3.0 through 3.6 releases.
  • Review mail and message gateway logs for malformed or oversized ASN.1 AEAD parameter errors.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703 Patch
https://github.com/openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9 Patch
https://github.com/openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3 Patch
https://github.com/openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e Patch
https://github.com/openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc Patch
https://openssl-library.org/news/secadv/20260127.txt Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/01/27/10 Mailing List
http://www.openwall.com/lists/oss-security/2026/02/25/6 Mailing List
https://access.redhat.com/errata/RHSA-2026:1472
https://access.redhat.com/errata/RHSA-2026:1473
https://access.redhat.com/errata/RHSA-2026:1496
https://access.redhat.com/errata/RHSA-2026:1503
https://access.redhat.com/errata/RHSA-2026:1519
https://access.redhat.com/errata/RHSA-2026:1594
https://access.redhat.com/errata/RHSA-2026:1733
https://access.redhat.com/errata/RHSA-2026:1736
https://access.redhat.com/errata/RHSA-2026:2072
https://access.redhat.com/errata/RHSA-2026:2077
https://access.redhat.com/errata/RHSA-2026:2485
https://access.redhat.com/errata/RHSA-2026:2563
https://access.redhat.com/errata/RHSA-2026:2633
https://access.redhat.com/errata/RHSA-2026:2659
https://access.redhat.com/errata/RHSA-2026:2671
https://access.redhat.com/errata/RHSA-2026:2844
https://access.redhat.com/errata/RHSA-2026:2974
https://access.redhat.com/errata/RHSA-2026:2995
https://access.redhat.com/errata/RHSA-2026:3228
https://access.redhat.com/errata/RHSA-2026:3415
https://access.redhat.com/errata/RHSA-2026:3461
https://access.redhat.com/errata/RHSA-2026:3462
https://access.redhat.com/errata/RHSA-2026:4419
https://access.redhat.com/errata/RHSA-2026:4943
https://access.redhat.com/errata/RHSA-2026:6481
https://access.redhat.com/errata/RHSA-2026:7261
https://access.redhat.com/security/cve/CVE-2025-15467
https://bugzilla.redhat.com/show_bug.cgi?id=2430376
https://cert-portal.siemens.com/productcert/html/ssa-434797.html
https://cert-portal.siemens.com/productcert/html/ssa-734552.html
https://github.com/guiimoraes/CVE-2025-15467 ExploitThird Party Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json

Track CVE-2025-15467 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 6.5%10.0CVE-2006-3738OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher listOpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The …EPSS 49%analysed9.8CVE-2026-63073Openssl vulnerabilityIssue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_da…EPSS 1.2%9.8CVE-2026-31789Openssl out-of-bounds write vulnerabilityIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact…EPSS 0.33%9.8CVE-2022-2274OpenSSL 3.0.4 RSA AVX512IFMA memory corruptionOpenSSL 3.0.4 introduced a bug in the RSA implementation for X86_64 CPUs supporting AVX512IFMA instructions, causing 2048-bit private key operations …EPSS 46%analysed9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed9.8CVE-2016-6309OpenSSL 1.1.0a statem use-after-free on realloc in TLS session handlingOpenSSL 1.1.0a's statem/statem.c fails to account for memory-block movement after a realloc call, leaving a dangling pointer that can be used after f…EPSS 70%analysed

Source: NIST National Vulnerability Database (record CVE-2025-15467), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.