OpenSSL CMS Parsing Stack Buffer Overflow Can Cause Denial of Service or Remote Code Execution

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2025-15467?

CVE-2025-15467 is a vulnerability classified as Out-of-bounds Write, affecting OpenSSL (affected versions: 3.6.0 – < 3.6.1, 3.5.0 – < 3.5.5, and other affected versions). This vulnerability is rated Critical, with a CVSS score of 9.8. Public exploit code or evidence is available for this vulnerability, but that does not confirm exploitation in the wild.

Overview

Original source data

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.

Affected products and scope

  • OpenSSL from 3.6.0 before 3.6.1 is affected. OpenSSL 3.6.1 is the confirmed fixed release for this branch.
  • OpenSSL from 3.5.0 before 3.5.5 is affected. OpenSSL 3.5.5 is the confirmed fixed release for this branch.
  • OpenSSL from 3.4.0 before 3.4.4 is affected. OpenSSL 3.4.4 is the confirmed fixed release for this branch.
  • OpenSSL from 3.3.0 before 3.3.6 is affected. OpenSSL 3.3.6 is the confirmed fixed release for this branch.
  • OpenSSL from 3.0.0 before 3.0.19 is affected. OpenSSL 3.0.19 is the confirmed fixed release for this branch.
  • OpenSSL 1.1.1 and 1.0.2 are not affected according to the advisory. The FIPS modules in 3.6, 3.5, 3.4, 3.3, and 3.0 are not affected because the CMS implementation is outside the FIPS module boundary.
  • The supplied record does not establish the status of branches outside those listed above.

Technical details

When parsing CMS AuthEnvelopedData or EnvelopedData structures that use AEAD ciphers such as AES-GCM, OpenSSL copies the IV encoded in ASN.1 parameters into a fixed-size stack buffer without checking its length. An oversized IV can cause a stack-based out-of-bounds write before authentication or tag verification occurs. An attacker only needs to deliver a crafted CMS or PKCS#7 message to an application that parses it; valid key material is not required to trigger the flaw. Network or local reachability depends on which application accepts and processes the content. Turning the stack write primitive into remote code execution depends on platform and toolchain mitigations, so RCE cannot be assumed across all environments. CMS is outside the boundary of the FIPS modules identified by the advisory, so the FIPS-module status does not replace assessment of applications using CMS outside that boundary.

Exploitability

  • The flaw can be triggered when an application or service parses untrusted CMS or PKCS#7 content with an AEAD cipher, such as S/MIME AuthEnvelopedData using AES-GCM.
  • The out-of-bounds write occurs before authentication or tag verification, so valid key material is not required. The attacker must still deliver the content to a vulnerable parser, and the delivery path depends on the deployment.
  • Not every deployment is established to be directly reachable over a network. Some deployments may require a user or workflow to process the message before the parser is invoked.
  • A third-party public exploit repository has been identified. Its contents do not establish that RCE works across all platforms, because OpenSSL describes the RCE outcome as dependent on platform and toolchain mitigations.
  • The supplied record and reviewed sources do not establish a specific campaign, victim, or confirmed real-world exploitation activity.

Technical impact

The flaw creates a stack-based out-of-bounds write in the process parsing the CMS message, which may corrupt execution state and cause a crash. Under suitable conditions, the write primitive may be turned into remote code execution, but OpenSSL does not establish that outcome for every platform or hardening configuration. If code execution occurs, it would normally have the privileges of the affected process; privilege escalation is not established by the available evidence. Organisational consequences could therefore include service interruption and loss of confidentiality or integrity for data accessible to the process, but the flaw alone is not evidence that a compromise has occurred.

Business impact

  • Applications processing CMS or S/MIME content may terminate when they receive a crafted message, disrupting services and workflows for email, document signing, or certificate management.
  • If the stack write is successfully turned into code execution, the affected process could be controlled within its existing privileges, creating potential confidentiality, integrity, and availability consequences for the data it can access.
  • The evidence does not establish that every deployment enables RCE or that a data breach has occurred. Actual impact depends on the calling application, process privileges, and runtime protections.
  • Systems that use a FIPS module still require separate assessment if their applications use CMS code outside the module boundary.

Remediation

  1. Upgrade OpenSSL to the fixed release for the deployed branch: 3.6.1, 3.5.5, 3.4.4, 3.3.6, or 3.0.19.
  2. Prioritize updates for services, mail clients, and applications that accept or parse untrusted CMS, PKCS#7, or S/MIME content. Verify the library actually loaded at runtime rather than relying only on package metadata.
  3. Until updates are complete, if operationally feasible, prevent untrusted CMS or PKCS#7 content from reaching the vulnerable parser or isolate the content-processing workflow. This is general precautionary guidance, not a vendor-confirmed mitigation.
  4. After updating, restart or replace processes, containers, and images that loaded the old OpenSSL library, then recheck the inventory to confirm that affected branches are no longer deployed.
  5. Do not treat FIPS-module use as proof that the complete application is safe. The advisory excludes CMS outside the FIPS module boundary, so applications that call CMS must be assessed and updated separately.

Detection

  1. Inventory the OpenSSL versions actually used by services, mail clients, and document-processing applications, especially components that parse CMS, PKCS#7, or S/MIME.
  2. Identify workflows that accept untrusted CMS content and use AEAD ciphers such as AES-GCM. Check the library loaded at runtime, not only the operating system package metadata.
  3. Compare each deployed version with the affected branches and corresponding fixed releases in affected_summary, then verify that the process was restarted or the image replaced after updating.
  4. Review crashes, abnormal terminations, or parsing errors in processes handling CMS after receiving untrusted content. This is precautionary monitoring, not a confirmed issue-specific indicator.
  5. No specific IOC is established by the evidence reviewed. The absence of crash logs does not prove safety because some workflows may not record the event completely.
Sources (55)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan