PT-2025-47819 · Unknown+1 · Xchacha20-Poly1305+1

Luigino Camastra

·

Published

2025-11-21

·

Updated

2025-12-04

·

CVE-2025-11931

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Versions prior to 2025-11931
Description An integer underflow can lead to out-of-bounds access during decryption using XChaCha20-Poly1305. This occurs specifically when calling the wc XChaCha20Poly1305 Decrypt() function, which is utilized by direct application calls and not through TLS connections.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Underflow

Weakness Enumeration

Related Identifiers

CVE-2025-11931

Affected Products

Debian
Xchacha20-Poly1305