CVE-2025-15467
OpenSSL OpenSSL, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a...
- CVSS
- 8.8
- EPSS
- 47.6% 98.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.01.28