This update for openssl-3 fixes the following issues:
- CVE-2025-9230: Fixed out-of-bounds read & write in RFC 3211 KEK unwrap (bsc#1250232)
- CVE-2025-9231: Fixedk timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233)
- CVE-2025-9232: Fixed out-of-bounds read in HTTP client no_proxy handling (bsc#1250234)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-107=1
- openSUSE Leap 16.0:
libopenssl-3-devel-3.5.0-160000.4.1
libopenssl-3-fips-provider-3.5.0-160000.4.1
libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.4.1
libopenssl3-3.5.0-160000.4.1
libopenssl3-x86-64-v3-3.5.0-160000.4.1
openssl-3-3.5.0-160000.4.1
openssl-3-doc-3.5.0-160000.4.1
* bsc#1250232
* bsc#1250233
* bsc#1250234
References:
* https://www.suse.com/security/cve/CVE-2025-9230.html
* https://www.suse.com/security/cve/CVE-2025-9231.html
* https://www.suse.com/security/cve/CVE-2025-9232.html
Get the latest Linux and open source security news straight to your inbox.