vulnerability

Ubuntu: USN-7786-1 (CVE-2025-9230): OpenSSL vulnerabilities

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Sep 30, 2025
Added
Oct 1, 2025
Modified
Oct 6, 2025

Description

Stanislav Fort discovered that OpenSSL incorrectly handled memory when
trying to decrypt CMS messages encrypted with password-based encryption. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2025-9230)

Stanislav Fort discovered that OpenSSL had a timing side-channel in SM2
signature computations on ARM platforms. A remote attacker could possibly
use this issue to recover private data. This issue only affected Ubuntu
25.04. (CVE-2025-9231)

Stanislav Fort discovered that OpenSSL incorrectly handled memory during
HTTP requests when "no_proxy" environment variable is set. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 25.04. (CVE-2025-9232)

Solutions

ubuntu-pro-upgrade-libssl1-0-0ubuntu-pro-upgrade-libssl1-1ubuntu-pro-upgrade-libssl3ubuntu-pro-upgrade-libssl3t64ubuntu-pro-upgrade-opensslubuntu-pro-upgrade-openssl1-0
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.