PT-2025-54285 · Libsodium+4 · Libsodium+4
Frank Denis
·
Published
2025-01-01
·
Updated
2026-05-12
·
CVE-2025-69277
CVSS v3.1
4.5
Medium
| Vector | AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
libsodium versions prior to ad3004e
Description
The software mishandles checks for the validity of elliptic curve points in specific, unusual scenarios. This occurs when custom cryptography or untrusted data is used with the
crypto core ed25519 is valid point function, potentially allowing points that are not part of the main cryptographic group.Recommendations
Update to version ad3004e or later.
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Red Os
Ubuntu
Libsodium