---
title: "CVE-2025-9231\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-9231?format=md
keywords: index, follow
---

# CVE-2025-9231

Publication date 30 September 2025

Last updated 8 October 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2025-9231?format=md#impact-score)

Toggle side navigation

## Description

Issue summary: A timing side-channel which could potentially allow remote
recovery of the private key exists in the SM2 algorithm implementation on
64 bit
ARM platforms.
Impact summary: A timing side-channel in SM2 signature computations on 64
bit
ARM platforms could allow recovering the private key by an attacker..
While remote key recovery over a network was not attempted by the reporter,
timing measurements revealed a timing signal which may allow such an
attack.
OpenSSL does not directly support certificates with SM2 keys in TLS, and so
this CVE is not relevant in most TLS contexts. However, given that it is
possible to add support for such certificates via a custom provider,
coupled
with the fact that in such a custom provider context the private key may be
recoverable via remote timing measurements, we consider this to be a
Moderate
severity issue.
The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by
this
issue, as SM2 is not an approved algorithm.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-9231?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| nodejs | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Vulnerable |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Not affected |
| edk2 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| openssl | 26.04 LTS resolute | Fixed 3.5.3-1ubuntu2 |
| 25.10 questing | Fixed 3.5.3-1ubuntu2 |
| 25.04 plucky | Fixed 3.4.1-1ubuntu4 |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| openssl1.0 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 18.04 LTS bionic | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2025-9231?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

3.1, 3.0, 1.1.1 and 1.0.2 are not vulnerable to this issue

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| openssl | * Upstream:   [eed5adc](https://github.com/openssl/openssl/commit/eed5adc9f969d77c94f213767acbb41ff923b6f4) * Upstream:   [cd6187c](https://github.com/openssl/openssl/commit/cd6187c7ac677d73da9ad374a5d86d80a3e7bf94) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | None |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-9231)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-9231)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-9231)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-9231)

### Related Ubuntu Security Notices (USN)

+ [USN-7786-1](https://usn.ubuntu.com/USN-7786-1)
+ OpenSSL vulnerabilities
+ 30 September 2025

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-9231>
