CVE-2025-68160Out-of-bounds Write in Openssl

CWE-787Out-of-bounds Write14 documents9 sources
Severity
4.7MEDIUMNVD
OSV6.1
EPSS
0.0%
top 92.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 27

Description

Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages5 packages

CVEListV5openssl/openssl3.6.03.6.1+6
NVDopenssl/openssl1.0.21.0.2zn+6
Alpineopenssl/openssl< 3.0.19-r0+4
Debianopenssl/openssl< 1.1.1w-0+deb11u5+3
Ubuntuopenssl/openssl< 3.0.2-0ubuntu1.21+10

Patches

🔴Vulnerability Details

7
OSV
CVE-2025-68160: Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger2026-01-27
OSV
openssl, openssl1.0 vulnerabilities2026-01-27
OSV
CVE-2025-68160: Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger2026-01-27
OSV
openssl vulnerabilities2026-01-27
OSV
CVE-2025-68160: Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger2026-01-27

📋Vendor Advisories

5
Red Hat
openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter2026-01-27
Ubuntu
OpenSSL vulnerabilities2026-01-27
BSD
FreeBSD-SA-26:01.openssl: Multiple vulnerabilities in OpenSSL2026-01-27
Ubuntu
OpenSSL vulnerabilities2026-01-27
Debian
CVE-2025-68160: openssl - Issue summary: Writing large, newline-free data into a BIO chain using the line-...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-68160 Impact, Exploitability, and Mitigation Steps | Wiz