PT-2025-15361 · Unknown+5 · Rust-Openssl+5

CVE-2025-3416

·

Published

2025-04-04

·

Updated

2026-07-23

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified) rust-openssl crate versions prior to 0.10.71
Description A flaw exists in the handling of the properties argument within certain functions. This issue can lead to a use-after-free condition, which may result in undefined behavior or incorrect property parsing, causing the system to treat the input as an empty string. In the rust-openssl crate, this specifically affects the Md::fetch() and Cipher::fetch() functions. Exploitation of this memory corruption could potentially allow a remote attacker to execute arbitrary code or cause a denial of service.
Recommendations Update the rust-openssl crate to version 0.10.71 or later. As a temporary mitigation, restrict the use of the Md::fetch() and Cipher::fetch() functions until the update is applied.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-61804
BDU:2025-12888
CVE-2025-3416
OESA-2026-2944
OESA-2026-2945
OESA-2026-2946
OPENSUSE-SU-2025:0152-1
OPENSUSE-SU-2025:15056-1
OPENSUSE-SU-2025:15057-1
OPENSUSE-SU-2025:15060-1
OPENSUSE-SU-2025:15061-1
OPENSUSE-SU-2025:15062-1
OPENSUSE-SU-2025:15063-1
OPENSUSE-SU-2025:15065-1
OPENSUSE-SU-2025:15066-1
OPENSUSE-SU-2025:15068-1
OPENSUSE-SU-2025:15071-1
OPENSUSE-SU-2025:15173-1
OPENSUSE-SU-2025:15217-1
OPENSUSE-SU-2025:15238-1
OPENSUSE-SU-2025:15346-1
OPENSUSE-SU-2025_01591-1
OPENSUSE-SU-2025_01619-1
OPENSUSE-SU-2025_01631-1
OPENSUSE-SU-2025_01662-1
OPENSUSE-SU-2025_1560-1
OPENSUSE-SU-2025_1570-1
SUSE-SU-2025:01591-1
SUSE-SU-2025:01619-1
SUSE-SU-2025:01631-1
SUSE-SU-2025:01662-1
SUSE-SU-2025:01662-2
SUSE-SU-2025:01806-1
SUSE-SU-2025:01807-1
SUSE-SU-2025:01818-1
SUSE-SU-2025:02017-1
SUSE-SU-2025:02166-1
SUSE-SU-2025:02809-1
SUSE-SU-2025:02810-1
SUSE-SU-2025:02811-1
SUSE-SU-2025:02896-1
SUSE-SU-2025:03298-1
SUSE-SU-2025:03306-1
SUSE-SU-2025:03307-1
SUSE-SU-2025:03445-1
SUSE-SU-2025:1560-1
SUSE-SU-2025:1570-1
SUSE-SU-2025:20352-1
SUSE-SU-2025:20365-1
SUSE-SU-2025:20407-1
SUSE-SU-2025:20429-1
SUSE-SU-2025:20463-1
SUSE-SU-2025:20474-1
SUSE-SU-2025:20716-1
SUSE-SU-2025:20717-1
SUSE-SU-2025:20783-1
SUSE-SU-2025:20858-1
SUSE-SU-2025:3783-1
SUSE-SU-2025:3784-1
SUSE-SU-2025:3785-1
SUSE-SU-2025:3786-1
SUSE-SU-2025_01619-1
SUSE-SU-2025_01631-1
SUSE-SU-2025_01806-1
SUSE-SU-2025_01807-1
SUSE-SU-2025_01818-1
SUSE-SU-2025_02017-1
SUSE-SU-2025_02166-1
SUSE-SU-2025_03298-1
SUSE-SU-2025_03306-1
SUSE-SU-2025_03307-1
SUSE-SU-2025_03445-1
SUSE-SU-2026:0620-1
SUSE-SU-2026:22917-1
SUSE-SU-2026:3022-1
USN-7891-1

Affected Products

Debian
Linuxmint
Openssl
Suse
Ubuntu
Rust-Openssl