CVE-2025-69418
Last modified
CVE-2025-69418 is a medium-severity vulnerability rated 4/10 on the CVSS scale. Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.
Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | >= 1.1.1, < 1.1.1ze |
| Openssl | Openssl | >= 3.0.0, < 3.0.19 |
| Openssl | Openssl | >= 3.3.0, < 3.3.6 |
| Openssl | Openssl | >= 3.4.0, < 3.4.4 |
| Openssl | Openssl | >= 3.5.0, < 3.5.5 |
| Openssl | Openssl | >= 3.6.0, < 3.6.1 |
References
- https://openssl-library.org/news/secadv/20260127.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-69418?
How severe is CVE-2025-69418?
How do I fix CVE-2025-69418?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-69412KDE messagelib before 25.11.90 ignores SSL errors for threat…3.4
- CVE-2025-69413In Gitea before 1.25.2, /api/v1/user has different responses…5.3
- CVE-2025-69414Plex Media Server (PMS) through 1.42.2.10156 allows retrieva…7.1
- CVE-2025-69415In Plex Media Server (PMS) through 1.42.2.10156, ability to …7.1
- CVE-2025-69416In the plex.tv backend for Plex Media Server (PMS) through 2…4.3
- CVE-2025-69417In the plex.tv backend for Plex Media Server (PMS) through 2…4.3
- CVE-2025-69419Issue summary: Calling PKCS12_get_friendlyname() function on…7.4
- CVE-2025-6942The distributed engine versions 8.4.39.0 and earlier of Secr…3.8
- CVE-2025-69420Issue summary: A type confusion vulnerability exists in the …7.5
- CVE-2025-69421Issue summary: Processing a malformed PKCS#12 file can trigg…7.5
- CVE-2025-69425The Ruckus vRIoT IoT Controller firmware versions prior to 3…10
- CVE-2025-69426The Ruckus vRIoT IoT Controller firmware versions prior to 3…10
Are you affected by CVE-2025-69418?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
