ELA-1559-1 openssl security update

buffer overflow

2025-10-29
Packageopenssl
Version1.1.0l-1~deb9u11 (stretch)
Related CVEs CVE-2025-9230


Stanislav Fort discovered an out of bounds read and write issue when decrypting CMS messages that were encrypted using password based encryption.



For Debian 9 stretch, these problems have been fixed in version 1.1.0l-1~deb9u11.

We recommend that you upgrade your openssl packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.