Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

OpenSSL RFC 3211 KEK Unwrap Out-of-Bounds Read/Write

IdentifiersCVE-2025-9230CWE-787· Out-of-bounds Write

CVE-2025-9230 is an OpenSSL memory-safety vulnerability in RFC 3211 KEK Unwrap processing. According to the provided content, an application attempting to decrypt Cryptographic Message Syntax (CMS) messages encrypted using password-based encryption (PWRI) can trigger both an out-of-bounds read and an out-of-bounds write. The issue is described in OpenSSL advisories and release notes as affecting RFC 3211 KEK Unwrap handling during CMS decryption. The vulnerable condition occurs when processing specially crafted CMS content using password-based encryption support, a feature noted as rarely used. OpenSSL states that the FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1, and 3.0 are not affected because the CMS implementation is outside the OpenSSL FIPS module boundary.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can cause an application crash leading to denial of service via the out-of-bounds read. The out-of-bounds write can corrupt memory and may have more serious consequences, including denial of service or potential execution of attacker-supplied code. OpenSSL assessed exploitation as low probability, but the impact can still be severe if a target application processes attacker-controlled CMS PWRI messages.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by preventing untrusted CMS messages using password-based encryption (PWRI) from reaching vulnerable decryption paths. Disable or avoid CMS PWRI/RFC 3211 KEK unwrap functionality where feasible, and restrict processing of attacker-supplied CMS content to trusted sources only. There is no general complete workaround in the provided content; patching is the primary mitigation.

Remediation

Patch, then assume compromise.

Upgrade OpenSSL to a fixed release. The provided content states fixes were released on 2025-09-30 in OpenSSL 3.5.4, 3.4.3, 3.3.5, 3.2.6, and 3.0.18; premium-support-only fixes were also issued for 1.1.1zd and 1.0.2zm. Downstream products should be updated to vendor builds incorporating these fixes. Restart or redeploy applications linked against vulnerable OpenSSL versions after patching as appropriate.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
CanonicalNoble-Stemcell-Openstackoperating_system
FreebsdFreebsdapplication
OpenSSL Software FoundationOpensslapplication
Rocky LinuxRocky Linuxoperating_system
Rocky LinuxRocky Linuxoperating_system
TianocoreEdk2application

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity41

Community discussion across Reddit, Mastodon, and other social sources.