CVE-2025-9231
published 2025-09-30CVE-2025-9231: Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM…
PriorityP340medium6.5CVSS 3.1
AVNACLPRNUINSUCLINAL
EPSS
2.23%
80.8th percentile
Issue summary: A timing side-channel which could potentially allow remote
recovery of the private key exists in the SM2 algorithm implementation on 64 bit
ARM platforms.
Impact summary: A timing side-channel in SM2 signature computations on 64 bit
ARM platforms could allow recovering the private key by an attacker..
While remote key recovery over a network was not attempted by the reporter,
timing measurements revealed a timing signal which may allow such an attack.
OpenSSL does not directly support certificates with SM2 keys in TLS, and so
this CVE is not relevant in most TLS contexts. However, given that it is
possible to add support for such certificates via a custom provider, coupled
with the fact that in such a custom provider context the private key may be
recoverable via remote timing measurements, we consider this to be a Moderate
severity issue.
The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this
issue, as SM2 is not an approved algorithm.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 3.5.4-1 (forky) | openssl 3.5.4-1 (forky) |
| msrc | azl3_cloud-hypervisor_41.0.139-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_openssl_3.3.3-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-22_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-24_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cloud-hypervisor-cvm_38.0.72.2-5_on_cbl_mariner_2.0 | — | — |
| openssl | openssl | >= 0 < 0 | 0 |
| openssl | openssl | >= 0 < 3.3.5-r0 | 3.3.5-r0 |
| openssl | openssl | >= 0 < 3.3.5-r0 | 3.3.5-r0 |
| openssl | openssl | >= 0 < 3.5.4-r0 | 3.5.4-r0 |
| openssl | openssl | >= 0 < 3.5.4-r0 | 3.5.4-r0 |
| openssl | openssl | >= 0 < 3.5.1-1+deb13u1 | 3.5.1-1+deb13u1 |
| openssl | openssl | >= 0 < 3.5.4-1 | 3.5.4-1 |
| openssl | openssl | >= 0 < 3.0.2-0ubuntu1.20 | 3.0.2-0ubuntu1.20 |
| openssl | openssl | >= 0 < 3.0.13-0ubuntu3.6 | 3.0.13-0ubuntu3.6 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27+esm11 | 1.0.1f-1ubuntu2.27+esm11 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.20+esm13 | 1.0.2g-1ubuntu4.20+esm13 |
| openssl | openssl | >= 0 < 1.1.1-1ubuntu2.1~18.04.23+esm6 | 1.1.1-1ubuntu2.1~18.04.23+esm6 |
| openssl | openssl | >= 0 < 1.1.1f-1ubuntu2.24+esm1 | 1.1.1f-1ubuntu2.24+esm1 |
| openssl | openssl | >= 3.2.0 < 3.2.6 | 3.2.6 |
| openssl | openssl | >= 3.3.0 < 3.3.5 | 3.3.5 |
| openssl | openssl | >= 3.4.0 < 3.4.3 | 3.4.3 |
| openssl | openssl | >= 3.5.0 < 3.5.4 | 3.5.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5LOW
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-25:08.openssl: Multiple vulnerabilities in OpenSSL
bsd_advisories·2025-09-30·CVSS 7.5
CVE-2025-9230 [HIGH] FreeBSD-SA-25:08.openssl: Multiple vulnerabilities in OpenSSL
FreeBSD-SA-25:08.openssl Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in OpenSSL
Category: contrib
Module: openssl
Announced: 2025-09-30
Credits: Stanislav Fort (Aisle Research)
Affects: All supported versions of FreeBSD.
Corrected: 2025-09-30 15:26:14 UTC (stable/15, 15.0-ALPHA4)
2025-09-30 15:28:38 UTC (stable/14, 14.3-STABLE)
2025-09-30 15:37:16 UTC (releng/14.3, 14.3-RELEASE-p4)
2025-09-30 15:37:25 UTC (releng/14.2, 14.2-RELEASE-p7)
2025-09-30 15:30:02 UTC (stable/13, 13.5-STABLE)
2025-09-30 15:37:35 UTC (releng/13.5, 13.5-RELEASE-p5)
CVE Name: CVE-2025-9230, CVE-2025-9231, CVE-2025-9232
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2025-09-30·CVSS 7.5
CVE-2025-9232 [HIGH] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Stanislav Fort discovered that OpenSSL incorrectly handled memory when
trying to decrypt CMS messages encrypted with password-based encryption. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2025-9230)
Stanislav Fort discovered that OpenSSL had a timing side-channel in SM2
signature computations on ARM platforms. A remote attacker could possibly
use this issue to recover private data. This issue only affected Ubuntu
25.04. (CVE-2025-9231)
Stanislav Fort discovered that OpenSSL incorrectly handled memory during
HTTP requests when "no_proxy" environment variable is set. An attacker
could possibly use this issue to cause a denial of service. This i
Red Hat
openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
vendor_redhat·2025-09-30·CVSS 6.5
CVE-2025-9231 [MEDIUM] CWE-208 openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
Issue summary: A timing side-channel which could potentially allow remote
recovery of the private key exists in the SM2 algorithm implementation on 64 bit
ARM platforms.
Impact summary: A timing side-channel in SM2 signature computations on 64 bit
ARM platforms could allow recovering the private key by an attacker..
While remote key recovery over a network was not attempted by the reporter,
timing measurements revealed a timing signal which may allow such an attack.
OpenSSL does not directly support certificates with SM2 keys in TLS, and so
this CVE is not relevant in most TLS contexts. However, given that it is
possible to add support for such certificates via a custom provider, coupled
with the fact that in such a custom provid
Microsoft
Timing side-channel in SM2 algorithm on 64 bit ARM
vendor_msrc·2025-09-09·CVSS 6.5
CVE-2025-9231 [MEDIUM] CWE-385 Timing side-channel in SM2 algorithm on 64 bit ARM
Timing side-channel in SM2 algorithm on 64 bit ARM
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Debian
CVE-2025-9231: openssl - Issue summary: A timing side-channel which could potentially allow remote recove...
vendor_debian·2025·CVSS 6.5
CVE-2025-9231 [MEDIUM] CVE-2025-9231: openssl - Issue summary: A timing side-channel which could potentially allow remote recove...
Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a timing signal which may allow such an attack. OpenSSL does not directly support certificates with SM2 keys in TLS, and so this CVE is not relevant in most TLS contexts. However, given that it is possible to add support for such certificates via a custom provider, coupled with the fact that in such a custom provider context the private key may be recoverable via remote timi
Citrix
Citrix Security Bulletin CTX220138
vendor_citrix·CVSS 7.5
CVE-2017-9231 [HIGH] Citrix Security Bulletin CTX220138
Citrix Security Bulletin CTX220138
CVE References: CVE-2017-9231, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
OSV
openssl, openssl1.0 vulnerabilities
osv·2025-09-30·CVSS 7.5
CVE-2025-9230 [HIGH] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Stanislav Fort discovered that OpenSSL incorrectly handled memory when
trying to decrypt CMS messages encrypted with password-based encryption. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2025-9230)
Stanislav Fort discovered that OpenSSL had a timing side-channel in SM2
signature computations on ARM platforms. A remote attacker could possibly
use this issue to recover private data. This issue only affected Ubuntu
25.04. (CVE-2025-9231)
Stanislav Fort discovered that OpenSSL incorrectly handled memory during
HTTP requests when "no_proxy" environment variable is set. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 25.04. (CVE-2025-9232)
GHSA
GHSA-9mrx-mqmg-gwj9: Issue summary: A timing side-channel which could potentially allow remote
recovery of the private key exists in the SM2 algorithm implementation on 64
ghsa_unreviewed·2025-09-30
CVE-2025-9231 [MEDIUM] CWE-385 GHSA-9mrx-mqmg-gwj9: Issue summary: A timing side-channel which could potentially allow remote
recovery of the private key exists in the SM2 algorithm implementation on 64
Issue summary: A timing side-channel which could potentially allow remote
recovery of the private key exists in the SM2 algorithm implementation on 64 bit
ARM platforms.
Impact summary: A timing side-channel in SM2 signature computations on 64 bit
ARM platforms could allow recovering the private key by an attacker..
While remote key recovery over a network was not attempted by the reporter,
timing measurements revealed a timing signal which may allow such an attack.
OpenSSL does not directly support certificates with SM2 keys in TLS, and so
this CVE is not relevant in most TLS contexts. However, given that it is
possible to add support for such certificates via a custom provider, coupled
with the fact that in such a custom provider context the private key may be
recoverable via remote t
OSV
CVE-2025-9231: Issue summary: A timing side-channel which could potentially allow remote
recovery of the private key exists in the SM2 algorithm implementation on 64
osv·2025-09-30·CVSS 6.5
CVE-2025-9231 [MEDIUM] CVE-2025-9231: Issue summary: A timing side-channel which could potentially allow remote
recovery of the private key exists in the SM2 algorithm implementation on 64
Issue summary: A timing side-channel which could potentially allow remote
recovery of the private key exists in the SM2 algorithm implementation on 64 bit
ARM platforms.
Impact summary: A timing side-channel in SM2 signature computations on 64 bit
ARM platforms could allow recovering the private key by an attacker..
While remote key recovery over a network was not attempted by the reporter,
timing measurements revealed a timing signal which may allow such an attack.
OpenSSL does not directly support certificates with SM2 keys in TLS, and so
this CVE is not relevant in most TLS contexts. However, given that it is
possible to add support for such certificates via a custom provider, coupled
with the fact that in such a custom provider context the private key may be
recoverable via remote t
OSV
CVE-2025-9231: Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64
osv·2025-09-30·CVSS 6.5
CVE-2025-9231 [MEDIUM] CVE-2025-9231: Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64
Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a timing signal which may allow such an attack. OpenSSL does not directly support certificates with SM2 keys in TLS, and so this CVE is not relevant in most TLS contexts. However, given that it is possible to add support for such certificates via a custom provider, coupled with the fact that in such a custom provider context the private key may be recoverable via remote timi
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-9231 sslscan: Timing side-channel in SM2 algorithm on 64 bit ARM [fedora-42]
bugzilla·2025-10-01·CVSS 6.5
CVE-2025-9231 [MEDIUM] CVE-2025-9231 sslscan: Timing side-channel in SM2 algorithm on 64 bit ARM [fedora-42]
CVE-2025-9231 sslscan: Timing side-channel in SM2 algorithm on 64 bit ARM [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug re
Bugzilla
CVE-2025-9231 mingw-openssl: Timing side-channel in SM2 algorithm on 64 bit ARM [fedora-42]
bugzilla·2025-10-01·CVSS 6.5
CVE-2025-9231 [MEDIUM] CVE-2025-9231 mingw-openssl: Timing side-channel in SM2 algorithm on 64 bit ARM [fedora-42]
CVE-2025-9231 mingw-openssl: Timing side-channel in SM2 algorithm on 64 bit ARM [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all
Bugzilla
CVE-2025-9231 edk2: Timing side-channel in SM2 algorithm on 64 bit ARM [fedora-42]
bugzilla·2025-10-01·CVSS 6.5
CVE-2025-9231 [MEDIUM] CVE-2025-9231 edk2: Timing side-channel in SM2 algorithm on 64 bit ARM [fedora-42]
CVE-2025-9231 edk2: Timing side-channel in SM2 algorithm on 64 bit ARM [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug repor
Bugzilla
CVE-2025-9231 openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
bugzilla·2025-09-17·CVSS 6.5
CVE-2025-9231 [MEDIUM] CVE-2025-9231 openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
CVE-2025-9231 openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
Issue summary: A timing side-channel which could potentially allow remote
recovery of the private key exists in the SM2 algorithm implementation on 64 bit
ARM platforms.
Impact summary: A timing side-channel in SM2 signature computations on 64 bit
ARM platforms could allow recovering the private key by an attacker.
While remote key recovery over a network was not attempted by the reporter,
timing measurements revealed a timing signal which may allow such an attack.
OpenSSL does not directly support certificates with SM2 keys in TLS, and so
this CVE is not relevant in most TLS contexts. However, given that it is
possible to add support for such certificates via a custom provider, coupled
with the fact that in such
https://github.com/openssl/openssl/commit/567f64386e43683888212226824b6a179885a0fehttps://github.com/openssl/openssl/commit/cba616c26ac8e7b37de5e77762e505ba5ca51698https://github.com/openssl/openssl/commit/eed5adc9f969d77c94f213767acbb41ff923b6f4https://github.com/openssl/openssl/commit/fc47a2ec078912b3e914fab5734535e76c4820c2https://openssl-library.org/news/secadv/20250930.txthttp://www.openwall.com/lists/oss-security/2025/09/30/5http://www.openwall.com/lists/oss-security/2026/05/11/11https://cert-portal.siemens.com/productcert/html/ssa-032379.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-089022.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-253495.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-585531.html
2025-09-30
Published