CVE-2025-69418Patch(openssl / openssl)

LOWCVSS 4.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-325

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-01-27); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-01-27: 2Mentions · 2026-01-28: 1Mentions · 2026-01-30: 1Mentions · 2026-02-19: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-30: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-19: 101-2701-2801-3002-1903-1403-15
Signal classification3 categories
Patch
457.1%
Disclosure
228.6%
General
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure1Patch1
2026-01-281
Patch1
2026-01-301
Patch1
2026-02-191
Disclosure1
2026-03-141
General1
2026-03-151
Patch1
Full discourse7 posts
  • Paul Ducklin@duckblog
    Patch

    OpenSSL 3.6.1 (and similar updates for older supported versions) is out, with 12 security fixes. Funkiest flaw? CVE-2025-69418, where some AES encryptions could leave the last 1 to 15 bytes of input unencrypted and unauthenticated. Patch early, patch often! https://t.co/oNBjsBPuGT

    Post summary

    OpenSSL 3.6.1 has been released with 12 security patches, including a fix for CVE‑2025‑69418 that prevents partial AES encryption leaks; users are urged to apply the update.

    02011225
    9.9K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-69418 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/418 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post announces that CVE-2025-69418 has been removed from the latest AWS Lambda base images, with no additional technical details, PoC, or exploit information provided.

    00000151
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-69418 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/418 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base image scans indicate that CVE-2025-69418 is no longer present in the latest images, suggesting it has been removed or fixed in newer releases.

    00000154
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2025-69418 impacts openssl-fips-provider-latest in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/418 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE (CVE‑2025‑69418) affecting the OpenSSL FIPS provider in AWS Lambda base images has been identified, with links for further details.

    0000041
    30 followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2025-69418 : OPENSSL OCB PARTIAL-BLOCK ENCRYPTION / AUTHENTICATION BYPASS ALERT 🚨 @openssl_  A vulnerability has been identified in OpenSSL’s low-level OCB mode implementation — where, under hardware-accelerated code paths, the final 1–15 bytes of non-16-byte-aligned messages may not be correctly encrypted/authenticated, enabling limited plaintext exposure and potential undetected modification of the message tail in niche application scenarios. Risk Severity: Low (upstream OpenSSL rating); practical exploitation is highly conditional and generally not applicable to standard TLS usage. Impact: • Disclosure of the last 1–15 bytes of affected OCB-encrypted messages (partial plaintext tail) • Potential undetected modification of trailing bytes in the affected partial block (integrity gap at message end) • Scope limited to non-block-aligned inputs and low-level OCB calls (not general OpenSSL usage) • Standard TLS services typically unaffected (OCB not used in TLS; EVP/high-level usage patterns not the exposed surface described) Root Cause: CWE-327 (Use of a Broken or Risky Cryptographic Algorithm) When applications directly use the low-level OCB API (CRYPTO_ocb128_encrypt() / CRYPTO_ocb128_decrypt()) with hardware acceleration (e.g., AES-NI) and non-16-byte-aligned message lengths, the accelerated path can mishandle the final partial block, leaving the tail insufficiently protected. Attackers can: • Identify a target application that explicitly calls CRYPTO_ocb128_encrypt/decrypt() in OCB mode (low-level API usage) • Ensure messages are not a multiple of 16 bytes so a 1–15 byte remainder exists[ citation:1] • Exploit the partial-block handling gap to observe or tamper with only the trailing bytes (bounded impact) • Leverage it only where they can influence or inspect ciphertext/message boundaries in that application protocol[ citation:3] Are You Affected? Vulnerable: • OpenSSL 3.0.0 through 3.6.0 in the scenarios described (low-level OCB API + hardware-accelerated path + non-block-aligned inputs). Fixed in: • OpenSSL 3.6.1. Note: Upstream rates this Low because the vulnerable surface is specialized (requires direct low-level OCB API usage). Most organizations using OpenSSL for TLS/web are not impacted. Immediate Action Required: Update/Patch: • Upgrade to OpenSSL 3.6.1 (or vendor backport containing the fix). Mitigation (if you truly use low-level OCB): • Audit for direct calls to CRYPTO_ocb128_encrypt() / CRYPTO_ocb128_decrypt() and migrate to safer/high-level patterns where possible. • If you cannot patch quickly and are confirmed exposed: consider temporary operational mitigations such as avoiding non-16-byte-aligned message lengths at the application layer (protocol padding/length rules). Audit & Monitor: • Locate any OCB usage and validate whether messages can end with a partial block; review protocol traces for non-16-byte-aligned payload lengths. • Confirm whether your OpenSSL build uses hardware acceleration paths on the affected platforms. Incident Response: • If you suspect misuse/exposure, scope the maximum leak to 1–15 bytes per affected message, then assess whether those tails can contain secrets; consider key/session rotation where warranted. This is a real crypto correctness bug with a clear fix, but risk is typically limited to niche, custom OCB low-level API usage—patching is still recommended for hygiene and assurance. 🛡️ #openssl #security #ostorlabCVE

    Post summary

    This advisory announces CVE‑2025‑69418, a low‑severity OpenSSL OCB partial‑block encryption flaw, provides detailed technical information, and recommends upgrading to OpenSSL 3.6.1 with additional mitigation steps.

    00000107
    581 followersView on X
  • 〒@teenigma_
    Disclosure

    oss-sec: OpenSSL Security Advisory Moderate: CVE-2025-11187 High: CVE-2025-15467 Low: CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://seclists.org/oss-sec/2026/q1/123

    Post summary

    An OpenSSL security advisory lists CVE-2025-11187, CVE-2025-15467, and a range of lower‑severity CVEs with ratings, but provides no technical details, PoC, exploit code, or patch information.

    00000156
    348 followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.1 Is Now Available with Important Security Patches and Bug Fixes This release addresses CVE-2025-11187, CVE-2025-15467, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, and CVE-2025-69419. https://9to5linux.com/openssl-3-6-1-is-now-available-with-important-security-patches-and-bug-fixes

    Post summary

    The article announces the release of OpenSSL 3.6.1, which includes patches for several CVEs. No PoC, exploit, or active exploitation claims are mentioned.

    00000158
    130 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more