Critical Vulnerability Information Vulnerability Identifier CVE ID: CVE-2025-3416 Impact Assessment CVSS v3 Base Score: 3.7 Severity: Low Impact Description Vulnerability Description: A vulnerability was discovered in OpenSSL when handling attribute parameters for certain functions. This flaw allows use-after-free conditions, potentially leading to undefined behavior or incorrect attribute parsing, causing OpenSSL to treat input as an empty string. Mitigation Measures Currently Available Mitigations: No available or currently applicable mitigations meet Red Hat Product Security standards, including usability and deployment, applicability to a broad installed base, and stability. Affected Packages and Red Hat Security Advisories Affected Products and Services: - Red Hat Directory Server 11 - Red Hat Directory Server 12 - Red Hat Enterprise Linux 6 - Red Hat Enterprise Linux 7 - Red Hat Enterprise Linux 8 - Other related components such as openssl, firefox, python312-cryptography, etc. CVSS v3 Score Details Attack Vector: Network Attack Complexity: High Required Privileges: None User Interaction: None Scope: Unchanged Confidentiality Impact: None Integrity Impact: None Availability Impact: Low Weakness Understanding (CWE) CWE ID: CWE-416 Weakness Type: Use After Free Technical Impact: Memory Modification, Crash, Exit or Reboot, Execution of Unauthorized Code or Commands Frequently Asked Questions Includes answers to common questions regarding vulnerability status in Red Hat products, remediation plans, and mitigation options.