CVE-2025-68160Patch(openssl / openssl)

LOWCVSS 4.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-01-27); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-01-27: 2Mentions · 2026-01-29: 1Mentions · 2026-02-03: 1Mentions · 2026-02-19: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-15: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-03: 101-2701-2902-0302-1903-1403-15
Signal classification2 categories
Patch
571.4%
Disclosure
228.6%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure1Patch1
2026-01-291
Patch1
2026-02-031
Patch1
2026-02-191
Disclosure1
2026-03-141
Patch1
2026-03-151
Patch1
Full discourse7 posts
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-68160 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/417 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The latest AWS Lambda base images have removed CVE-2025-68160, indicating that the vulnerability has been patched or otherwise mitigated.

    00000150
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-68160 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/417 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base images have eliminated CVE‑2025‑68160 following recent scans, indicating that a patch or mitigation has been applied; no exploit evidence or PoC details are provided.

    00000156
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2025-68160 impacts openssl-fips-provider-latest in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/417 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity vulnerability, CVE-2025-68160, has been identified in AWS Lambda base images affecting the OpenSSL FIPS provider. Detailed information is available through the linked GitHub issue and LambdaWatchdog.

    0000042
    30 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical #SUSE security update patches 7 #OpenSSL 1.1 vulnerabilities (CVE-2025-68160, CVE-2026-22795+). Affects SLES 15 SP4, openSUSE Leap 15.4, Micro distributions. Memory corruption, parsing flaws, encryption issues. Patch now! Read more: 👉 https://tinyurl.com/2a33bca3 #Security https://t.co/NJP1oMfkRX

    Post summary

    The tweet announces a SUSE security update addressing several OpenSSL 1.1 vulnerabilities (CVE-2025-68160, CVE-2026-22795+) with memory corruption, parsing, and encryption flaws, and urges users to apply the patch.

    0000060
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 #SUSE #OpenSSL 1.1 Security Update Alert! 🚨 Patch now: SUSE-SU-2026:0331-1 fixes 7 flaws (CVSS up to 6.2). Includes heap OOB write (CVE-2025-68160) & multiple ASN.1 type validation issues. Read more: 👉https://tinyurl.com/2ke7dauh #Security https://t.co/mW7hD8vWee

    Post summary

    The tweet announces a SUSE security update SUSE-SU-2026:0331-1 that patches seven flaws, including CVE-2025-68160, a heap out‑of‑bounds write, and several ASN.1 validation issues.

    00000103
    1.3K followersView on X
  • 〒@teenigma_
    Disclosure

    oss-sec: OpenSSL Security Advisory Moderate: CVE-2025-11187 High: CVE-2025-15467 Low: CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://seclists.org/oss-sec/2026/q1/123

    Post summary

    The advisory announces several OpenSSL CVEs with severity categories but provides no PoC, exploit code, active exploitation evidence, patch details, or technical specifics.

    00000156
    348 followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.1 Is Now Available with Important Security Patches and Bug Fixes This release addresses CVE-2025-11187, CVE-2025-15467, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, and CVE-2025-69419. https://9to5linux.com/openssl-3-6-1-is-now-available-with-important-security-patches-and-bug-fixes

    Post summary

    OpenSSL 3.6.1 release includes patches for multiple CVEs and addresses several security issues, offering updated bug fixes.

    00000158
    130 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more