CVE-2025-69419Patch(openssl / openssl)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer. The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-01-27); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-01-27: 2Mentions · 2026-02-19: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-07-22: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-07-22: 1Technical Details · 2026-02-19: 101-2702-1903-1403-1507-22
Signal classification2 categories
Patch
466.7%
Disclosure
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure1Patch1
2026-02-191
Disclosure1
2026-03-141
Patch1
2026-03-151
Patch1
2026-07-221
Patch1
Full discourse6 posts
  • Meridian Group@MeridianEU
    Patch

    HPE patches CVE-2025-69419 and CVE-2026-35554 in Telco Automated Assurance software v1.4 and earlier. Advisory co-issued with Canadian Centre for Cyber Security. No active exploitation reported; patching recommended. https://t.co/pGtbeGuIMK

    Post summary

    The tweet announces HPE patches for CVE‑2025‑69419 and CVE‑2026‑35554 in Telco Automated Assurance software, notes no active exploitation, and recommends applying the patch.

    0000044
    67 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-69419 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/419 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base images no longer contain CVE‑2025‑69419 per Lambda Watchdog scan, indicating the vulnerability has been removed or patched.

    00000151
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-69419 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/419 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The tweet states that CVE‑2025‑69419 is no longer present in the latest AWS Lambda base image scans, implying the vulnerability has been mitigated or patched, though no explicit patch instructions are provided.

    00000163
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2025-69419 impacts openssl-fips-provider-latest in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/419 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE-2025-69419 affecting openssl‑fips‑provider‑latest in 40 AWS Lambda base images has been identified, with links provided for further details.

    0000043
    30 followersView on X
  • 〒@teenigma_
    Disclosure

    oss-sec: OpenSSL Security Advisory Moderate: CVE-2025-11187 High: CVE-2025-15467 Low: CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://seclists.org/oss-sec/2026/q1/123

    Post summary

    The advisory announces a set of new OpenSSL CVEs with severity ratings, but does not provide additional technical or mitigation details.

    00000156
    348 followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.1 Is Now Available with Important Security Patches and Bug Fixes This release addresses CVE-2025-11187, CVE-2025-15467, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, and CVE-2025-69419. https://9to5linux.com/openssl-3-6-1-is-now-available-with-important-security-patches-and-bug-fixes

    Post summary

    The OpenSSL 3.6.1 release includes patches for several CVEs, but the text provides no exploit details or technical vulnerability specifics.

    00000158
    130 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more