Echo: openssl: security update to 3.5.1-1+deb13u1

medium Tenable Self-Hosted Container Security Plugin ID 461489

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Issue summary: A timing side-channel which could potentially allow remote recovery of the private key
exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel
in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an
attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements
revealed a timing signal which may allow such an attack. OpenSSL does not directly support certificates
with SM2 keys in TLS, and so this CVE is not relevant in most TLS contexts. However, given that it is
possible to add support for such certificates via a custom provider, coupled with the fact that in such a
custom provider context the private key may be recoverable via remote timing measurements, we consider
this to be a Moderate severity issue. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected
by this issue, as SM2 is not an approved algorithm. (CVE-2025-9231)

Solution

Update the openssl library and its related packages to version 3.5.1-1+deb13u1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-9231

Plugin Details

Severity: Medium

ID: 461489

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.83

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2025-9231

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/1/2025

Vulnerability Publication Date: 9/30/2025

Reference Information

CVE: CVE-2025-9231

IAVA: 2025-A-0716-S