CVE-2025-69420Improper Check for Unusual or Exceptional Conditions in Openssl

Severity
7.5HIGHNVD
OSV6.1
EPSS
0.3%
top 46.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 27

Description

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions oss

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

debiandebian/openssl< openssl 3.0.18-1~deb12u2 (bookworm)
NVDopenssl/openssl1.1.11.1.1ze+5
Alpineopenssl/openssl< 3.0.19-r0+4
Debianopenssl/openssl< 1.1.1w-0+deb11u5+3
Ubuntuopenssl/openssl< 3.0.2-0ubuntu1.21+9

Patches

🔴Vulnerability Details

6
OSV
openssl, openssl1.0 vulnerabilities2026-01-27
GHSA
GHSA-w42r-ph9f-9x66: Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without f2026-01-27
OSV
CVE-2025-69420: Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without f2026-01-27
OSV
openssl vulnerabilities2026-01-27
OSV
CVE-2025-69420: Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without f2026-01-27

📋Vendor Advisories

5
Red Hat
openssl: OpenSSL: Denial of Service via malformed TimeStamp Response2026-01-27
Ubuntu
OpenSSL vulnerabilities2026-01-27
BSD
FreeBSD-SA-26:01.openssl: Multiple vulnerabilities in OpenSSL2026-01-27
Ubuntu
OpenSSL vulnerabilities2026-01-27
Debian
CVE-2025-69420: openssl - Issue summary: A type confusion vulnerability exists in the TimeStamp Response v...2025

🕵️Threat Intelligence

12
Wiz
CVE-2025-15469 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-2673 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-69421 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-22796 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-15468 Impact, Exploitability, and Mitigation Steps | Wiz