VDB
RHSA-2025%3A9895
RHSA-2025%3A9895
PUBLISHED
CVSS 7.400000095367432 HIGH
A flaw was found in OpenSSL's RFC7250 Raw Public Key (RPK) authentication. This vulnerability allows man-in-the-middle (MITM) attacks via failure to abort TLS/DTLS handshakes when the server's RPK does not match the expected key despite the SSL_VERIFY_PEER verification mode being set.
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | service-interconnect/skupper-service-controller-rhel9@sha256:aa8406cdd6f52d3262575989db783e165986054152b24a82260fa493a93eb297_amd64 as a component of 9Base-Service-Interconnect-1.4 | * |
| Red Hat | service-interconnect/skupper-router-rhel9@sha256:84ea16f6b12159c0941d149dde8bc09739bfc5313f9d04a0ae8008aec25cd4af_amd64 as a component of 9Base-Service-Interconnect-1.4 | service-interconnect/skupper-router-rhel9@sha256:84ea16f6b12159c0941d149dde8bc09739bfc5313f9d04a0ae8008aec25cd4af_amd64 |
| Red Hat | service-interconnect/skupper-flow-collector-rhel9@sha256:51f9a24e3dc9b1d47c474fec5389e1e166f1a52f49940ca637755ea4fe5fd204_amd64 as a component of 9Base-Service-Interconnect-1.4 | service-interconnect/skupper-flow-collector-rhel9@sha256:51f9a24e3dc9b1d47c474fec5389e1e166f1a52f49940ca637755ea4fe5fd204_amd64 |
| Red Hat | service-interconnect/skupper-config-sync-rhel9@sha256:a8e4ab9a71183698ccead00ac54c354e6e749b0e85d82b6b3216c4e686944aff_amd64 as a component of 9Base-Service-Interconnect-1.4 | * |
| Red Hat | service-interconnect/skupper-operator-bundle@sha256:0f6c6faf7fdf7b6d69bc5cc4b0266064d0035e295d0562b957d95c8c81699f2b_amd64 as a component of 9Base-Service-Interconnect-1.4 | service-interconnect/skupper-operator-bundle@sha256:0f6c6faf7fdf7b6d69bc5cc4b0266064d0035e295d0562b957d95c8c81699f2b_amd64 |
| Red Hat | service-interconnect/skupper-site-controller-rhel9@sha256:5b6d67ddcb01f1ad961f1593bd29458d758b28c4166901d0a0d87fbb937b34a9_amd64 as a component of 9Base-Service-Interconnect-1.4 | service-interconnect/skupper-site-controller-rhel9@sha256:5b6d67ddcb01f1ad961f1593bd29458d758b28c4166901d0a0d87fbb937b34a9_amd64 |
Timeline
- Jun 30, 2025 CVE Published
- Apr 24, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:9895 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://docs.redhat.com/en/documentation/red_hat_service_interconnect/1.4 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2342757 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2346416 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2346421 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9895.json advisory
- https://access.redhat.com/security/cve/CVE-2024-12797 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-12797 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-12797 advisory
- https://openssl-library.org/news/secadv/20250211.txt advisory
- https://access.redhat.com/security/cve/CVE-2024-56171 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-56171 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-56171 advisory
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/828 advisory
- https://access.redhat.com/security/cve/CVE-2025-24928 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-24928 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-24928 advisory
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 advisory
- https://issues.oss-fuzz.com/issues/392687022 advisory