CVE-2025-15469Patch(openssl / openssl)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error. Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire file is authenticated while trailing data beyond 16MB remains unauthenticated. When the 'openssl dgst' command is used with algorithms that only support one-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input is buffered with a 16MB limit. If the input exceeds this limit, the tool silently truncates to the first 16MB and continues without signaling an error, contrary to what the documentation states. This creates an integrity gap where trailing bytes can be modified without detection if both signing and verification are performed using the same affected codepath. The issue affects only the command-line tool behavior. Verifiers that process the full message using library APIs will reject the signature, so the risk primarily affects workflows that both sign and verify with the affected 'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and library users are unaffected. The FIPS modules in 3.5 and 3.6 are not affected by this issue, as the command-line tools are outside the OpenSSL FIPS module boundary. OpenSSL 3.5 and 3.6 are vulnerable to this issue. OpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-01-27); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-01-27: 2Mentions · 2026-01-29: 2Mentions · 2026-02-05: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-01-29: 2Technical Details · 2026-02-05: 101-2701-2902-05
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure1Patch1
2026-01-292
Patch2
2026-02-051
General1
Full discourse5 posts
  • Daniel J. Bernstein@hashbreaker
    General

    One of the OpenSSL disasters announced last week (CVE-2025-15469) is really the fault of OpenSSL's detached-signature interface. With a signed-message/message-recovery interface, the bug would have had no effect on security, and would have been easier to catch. Interfaces matter.

    Post summary

    The post remarks on CVE‑2025‑15469, attributing the flaw to OpenSSL’s detached-signature interface without providing new exploit code, mitigation, or evidence of active exploitation.

    19051114.3K
    22.8K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl モジュール更新情報 3.5.5-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 openssl 3.5.5-1 この更新には脆弱性(CVE-2025-11187, CVE-2025-15469)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # dnf upgrade アップデート後、以下のコマ... https://kusanagi.tokyo/releases/22845/

    Post summary

    The message announces a Kusanagi-OpenSSL module update that applies security patches for CVE‑2025‑11187 and CVE‑2025‑15469.

    01020164
    196 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl Module Update 3.5.5-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: openssl 3.5.5-1 This update includes support for vulnerability(CVE-2025-11187, CVE-2025-15469). The module update can be applied... https://kusanagi.tokyo/en/releases/22846/

    Post summary

    Kusanagi’s OpenSSL module was updated to address CVE‑2025‑11187 and CVE‑2025‑15469, offering a patch via the new 3.5.5‑1 release.

    0000086
    196 followersView on X
  • 〒@teenigma_
    Disclosure

    oss-sec: OpenSSL Security Advisory Moderate: CVE-2025-11187 High: CVE-2025-15467 Low: CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://seclists.org/oss-sec/2026/q1/123

    Post summary

    The advisory lists several CVEs with severity levels and provides a link to a general advisory; no PoC, exploit, patch, or technical details are included.

    00000156
    348 followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.1 Is Now Available with Important Security Patches and Bug Fixes This release addresses CVE-2025-11187, CVE-2025-15467, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, and CVE-2025-69419. https://9to5linux.com/openssl-3-6-1-is-now-available-with-important-security-patches-and-bug-fixes

    Post summary

    The article announces that the new OpenSSL 3.6.1 release includes important security patches addressing several CVEs, emphasizing the availability of updates rather than exploit details.

    00000158
    130 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more