CVE-2015-3193: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 25.1% chance of exploitation in the next 30 days.

The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2) Diffie-Hellman Ephemeral (DHE) ciphersuite.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
  • Node.js Node.js: from 4.0.0, up to and including 4.1.2; from 4.2.0, before 4.2.3 (fixed in 4.2.3); from 5.0.0, before 5.1.1 (fixed in 5.1.1)
  • OpenSSL OpenSSL: version 1.0.2 only; version 1.0.2a only; version 1.0.2b only; version 1.0.2c only; version 1.0.2d only

Published 2015-12-06. Last modified 2026-06-17.