OpenSSL Advisory: September 30th, 2025 (BoringSSL Not Affected)

OpenSSL have published a security advisory. Here's how it affects BoringSSL:

CVESummarySeverity in OpenSSLImpact to BoringSSL
CVE-2025-9230Out-of-bounds read & write in RFC 3211 KEK UnwrapModerateNot affected, impacted code was removed from BoringSSL in the initial fork
CVE-2025-9231Timing side-channel in SM2 algorithm on 64 bit ARMModerateNot affected, issue was introduced after fork
CVE-2025-9232Out-of-bounds read in HTTP client no_proxy handlingLowNot affected, issue was introduced after fork