PT-2025-39987 · Openssl+3 · Openssl+3

Stanislav Fort

+1

·

Published

2025-09-30

·

Updated

2026-05-11

·

CVE-2025-9231

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 3.0.17-1~deb12u3 OpenSSL versions prior to 3.5.1-1+deb13u1 OpenSSL versions prior to 3.5.4 OpenSSL versions prior to 3.4.3 OpenSSL versions prior to 3.3.5 OpenSSL versions prior to 3.2.6
Description A timing side-channel exists in the SM2 algorithm implementation on 64-bit ARM platforms. This issue could potentially allow a remote attacker to recover the private key through precise timing measurements. While remote key recovery over a network has not been demonstrated, timing measurements have revealed a timing signal that may enable such an attack. The vulnerability is considered a moderate severity issue, particularly in scenarios where support for SM2 certificates is added via a custom provider. The FIPS modules in OpenSSL versions 3.0, 3.1, 3.2, 3.3, 3.4, and 3.5 are not affected, as SM2 is not an approved algorithm.
Recommendations Upgrade OpenSSL to version 3.0.17-1~deb12u3 or later. Upgrade OpenSSL to version 3.5.1-1+deb13u1 or later. Upgrade OpenSSL to version 3.5.4 or later. Upgrade OpenSSL to version 3.4.3 or later. Upgrade OpenSSL to version 3.3.5 or later. Upgrade OpenSSL to version 3.2.6 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-12886
CVE-2025-9231
DSA-6015-1
ECHO-2B7E-78D4-C817
JLSEC-2026-267
OPENSUSE-SU-2025:15723-1
OPENSUSE-SU-2025:20164-1
OPENSUSE-SU-2026:10237-1
RHSA-2026:7261
SUSE-SU-2025:21213-1
SUSE-SU-2025:21224-1
USN-7786-1

Affected Products

Freebsd
Linuxmint
Openssl
Ubuntu