Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-15467 Details

Description

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2026:1472 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:1473 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:1496 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:1503 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:1519 redhat-SADP

see all 40 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')redhat-SADP
CWE-787Out-of-bounds Write[email protected]

Affected Products

ProductVersions
openssl openssl
>= 3.0.0, < 3.0.19
>= 3.1.0, < 3.3.6
>= 3.4.0, < 3.4.4
>= 3.5.0, < 3.5.5
>= 3.6.0, < 3.6.1

CPE

  • cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

27 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-15467
NVD Published Date:
Jan 27, 2026
NVD Last Modified:
Sep 7, 2026
Source:
[email protected]
CVE-2025-15467 Details - Not Deferred