vulnerability

Ubuntu: (Multiple Advisories) (CVE-2025-9232): OpenSSL vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:C)
Published
Sep 30, 2025
Added
Oct 1, 2025
Modified
Nov 28, 2025

Description

Stanislav Fort discovered that OpenSSL incorrectly handled memory when
trying to decrypt CMS messages encrypted with password-based encryption. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2025-9230)

Stanislav Fort discovered that OpenSSL had a timing side-channel in SM2
signature computations on ARM platforms. A remote attacker could possibly
use this issue to recover private data. This issue only affected Ubuntu
25.04. (CVE-2025-9231)

Stanislav Fort discovered that OpenSSL incorrectly handled memory during
HTTP requests when "no_proxy" environment variable is set. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 25.04. (CVE-2025-9232)

Solutions

ubuntu-upgrade-libssl3t64ubuntu-upgrade-opensslubuntu-upgrade-ovmfubuntu-upgrade-ovmf-ia32ubuntu-upgrade-qemu-efiubuntu-upgrade-qemu-efi-aarch64ubuntu-upgrade-qemu-efi-armubuntu-upgrade-qemu-efi-loongarch64ubuntu-upgrade-qemu-efi-riscv64
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.