Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead t…
高危 CVSS 8.8
摘要
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its lengt…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703 Patch
- https://github.com/openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9 Patch
- https://github.com/openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3 Patch
- https://github.com/openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e Patch
- https://github.com/openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc Patch
- https://openssl-library.org/news/secadv/20260127.txt Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/01/27/10 Mailing List
- http://www.openwall.com/lists/oss-security/2026/02/25/6 Mailing List
- https://access.redhat.com/errata/RHSA-2026:1472
- https://access.redhat.com/errata/RHSA-2026:1473
- https://access.redhat.com/errata/RHSA-2026:1496
- https://access.redhat.com/errata/RHSA-2026:1503
- https://access.redhat.com/errata/RHSA-2026:1519
- https://access.redhat.com/errata/RHSA-2026:1594
- https://access.redhat.com/errata/RHSA-2026:1733
- https://access.redhat.com/errata/RHSA-2026:1736
- https://access.redhat.com/errata/RHSA-2026:2072
- https://access.redhat.com/errata/RHSA-2026:2077
- https://access.redhat.com/errata/RHSA-2026:2485
- https://access.redhat.com/errata/RHSA-2026:2563
- https://access.redhat.com/errata/RHSA-2026:2633
- https://access.redhat.com/errata/RHSA-2026:2659
- https://access.redhat.com/errata/RHSA-2026:2671
- https://access.redhat.com/errata/RHSA-2026:2844
- https://access.redhat.com/errata/RHSA-2026:2974
- https://access.redhat.com/errata/RHSA-2026:2995
- https://access.redhat.com/errata/RHSA-2026:3228
- https://access.redhat.com/errata/RHSA-2026:3415
- https://access.redhat.com/errata/RHSA-2026:3461
- https://access.redhat.com/errata/RHSA-2026:3462
- https://access.redhat.com/errata/RHSA-2026:4419
- https://access.redhat.com/errata/RHSA-2026:4943
- https://access.redhat.com/errata/RHSA-2026:6481
- https://access.redhat.com/errata/RHSA-2026:7261
- https://access.redhat.com/security/cve/CVE-2025-15467
- https://bugzilla.redhat.com/show_bug.cgi?id=2430376
- https://cert-portal.siemens.com/productcert/html/ssa-434797.html
- https://cert-portal.siemens.com/productcert/html/ssa-734552.html
- https://github.com/guiimoraes/CVE-2025-15467 Exploit
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json
时间线
- nvd_ingest NVD