Vulnerability record · CVE-2025-15467 · published 27 January 2026
CVE-2025-15467: OpenSSL CMS AEAD IV stack buffer overflow
OOpenssl · Openssl
OpenSSL 3.0 through 3.6 copies the AEAD initialization vector from CMS (Auth)EnvelopedData ASN.1 parameters into a fixed-size stack buffer without checking its length, so an oversized IV causes a stack out-of-bounds write. The write happens before any authentication or tag verification, so no valid key material is needed to trigger it. Applications parsing untrusted CMS or PKCS#7 content with AEAD ciphers such as AES-GCM (for example S/MIME) are exposed.
Description
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with a pre-authentication stack write and very high EPSS, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
OpenSSL 3.0 through 3.6 copies the AEAD initialization vector from CMS (Auth)EnvelopedData ASN.1 parameters into a fixed-size stack buffer without checking its length, so an oversized IV causes a stack out-of-bounds write. The write happens before any authentication or tag verification, so no valid key material is needed to trigger it. Applications parsing untrusted CMS or PKCS#7 content with AEAD ciphers such as AES-GCM (for example S/MIME) are exposed.
Impact
An attacker can crash the parsing process, causing denial of service, and the stack write primitive may allow remote code execution depending on platform and toolchain mitigations.
Attack surface
Reached remotely by delivering a crafted CMS or PKCS#7 message to a service or application that parses untrusted content with AEAD ciphers; the CVSS vector indicates no privileges are required but user interaction is needed. No valid key material is required because the overflow occurs before authentication.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is high at roughly 0.48 probability (98.8th percentile), and the references include only patches, a vendor advisory and mailing list posts.
What to do
- Upgrade OpenSSL to a release containing the fixes referenced by the five patch commits and the vendor advisory; 1.1.1 and 1.0.2 are not affected.
- Apply distribution errata (for example the listed Red Hat RHSA advisories) or vendor-supplied OpenSSL updates on affected hosts.
- Where immediate patching is not possible, avoid parsing untrusted CMS/PKCS#7 (Auth)EnvelopedData with AEAD ciphers, or restrict such parsing to trusted sources.
- Inventory applications and services that process S/MIME or CMS content with AES-GCM to confirm they link an affected OpenSSL 3.x version.
- Note that FIPS module versions 3.0 through 3.6 are not affected because the CMS implementation sits outside the FIPS module boundary.
Detection
- Monitor for crashes or abnormal termination in processes that parse CMS/PKCS#7 or S/MIME messages.
- Inspect CMS (Auth)EnvelopedData inputs for AEAD parameters carrying abnormally large IV values.
- Track OpenSSL library versions across hosts and flag any still on affected 3.0 through 3.6 releases.
- Review mail and message gateway logs for malformed or oversized ASN.1 AEAD parameter errors.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-15467 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-15467), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.