VDB
RHSA-2025%3A23202
RHSA-2025%3A23202
PUBLISHED
CVSS 5.599999904632568 MEDIUM
A flaw was found in the OpenSSL CMS implementation (RFC 3211 KEK Unwrap). This vulnerability allows memory corruption, an application level denial of service, or potential execution of attacker-supplied code via crafted CMS messages using password-based encryption (PWRI).
Risk Scores
CVSS 3.1
5.599999904632568
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:fca12d55fef49b9a67c8aa7c2c004adb8916b9784134b4e571067a615a7a4a2e_amd64 | |
| Red Hat | registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:fca12d55fef49b9a67c8aa7c2c004adb8916b9784134b4e571067a615a7a4a2e_amd64 as a component of Red Hat AI Inference Server 3.2 | *, registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:fca12d55fef49b9a67c8aa7c2c004adb8916b9784134b4e571067a615a7a4a2e_amd64, registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:fca12d55fef49b9a67c8aa7c2c004adb8916b9784134b4e571067a615a7a4a2e_amd64 |
| Red Hat | registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:f083e52ef4198ab8123c49eb044c4374ec996f65633d224bb8152ef0c3f30e7d_arm64 as a component of Red Hat AI Inference Server 3.2 | registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:f083e52ef4198ab8123c49eb044c4374ec996f65633d224bb8152ef0c3f30e7d_arm64, *, registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:f083e52ef4198ab8123c49eb044c4374ec996f65633d224bb8152ef0c3f30e7d_arm64 |
| Red Hat | registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:f083e52ef4198ab8123c49eb044c4374ec996f65633d224bb8152ef0c3f30e7d_arm64 as a component of Red Hat AI Inference Server 3.2 | registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:f083e52ef4198ab8123c49eb044c4374ec996f65633d224bb8152ef0c3f30e7d_arm64, *, * |
| Red Hat | registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:fca12d55fef49b9a67c8aa7c2c004adb8916b9784134b4e571067a615a7a4a2e_amd64 as a component of Red Hat AI Inference Server 3.2 | *, registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:fca12d55fef49b9a67c8aa7c2c004adb8916b9784134b4e571067a615a7a4a2e_amd64, registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:fca12d55fef49b9a67c8aa7c2c004adb8916b9784134b4e571067a615a7a4a2e_amd64 |
Timeline
- Dec 15, 2025 CVE Published
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Jun 18, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:23202 advisory
- https://access.redhat.com/security/cve/CVE-2025-22868 advisory
- https://access.redhat.com/security/cve/CVE-2025-22869 advisory
- https://access.redhat.com/security/cve/CVE-2025-52565 advisory
- https://access.redhat.com/security/cve/CVE-2025-59375 advisory
- https://access.redhat.com/security/cve/CVE-2025-66506 advisory
- https://access.redhat.com/security/cve/CVE-2025-9230 advisory
- https://access.redhat.com/security/cve/CVE-2025-9714 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://www.redhat.com/en/products/ai/inference-server advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23202.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2396054 issue
- https://www.cve.org/CVERecord?id=CVE-2025-9230 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-9230 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2392605 issue
- https://www.cve.org/CVERecord?id=CVE-2025-9714 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-9714 advisory
- https://gitlab.gnome.org/GNOME/libxml2/-/commit/677a42645ef22b5a50741bad5facf9d8a8bc6d21 advisory
- https://gitlab.gnome.org/GNOME/libxslt/-/issues/148 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2348366 issue
…and 25 more