Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-67897

Опубликовано: 14 дек. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

A flaw was found in Sequoia. This vulnerability allows a remote attacker to crash an application via sending a victim an encrypted message with a crafted Public Key Encrypted Session Key (PKESK) or Symmetric Key Encrypted Session Key (SKESK) packet, which causes aes_key_unwrap to panic when processing a short ciphertext.

Отчет

This vulnerability is rated Moderate for Red Hat. A remote attacker could crash an application using Sequoia by sending a specially crafted encrypted message. Successful exploitation requires high attack complexity and user interaction, as the victim must process the malicious message.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorFix deferred
Red Hat Enterprise Linux 10rust-rpm-sequoiaFix deferred
Red Hat Enterprise Linux 10rust-sequoia-sqFix deferred
Red Hat Enterprise Linux 10rust-sequoia-sqvFix deferred
Red Hat Enterprise Linux 10trustee-guest-componentsFix deferred
Red Hat Enterprise Linux 9rust-rpm-sequoiaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-195
https://bugzilla.redhat.com/show_bug.cgi?id=2422033Sequoia: Sequoia: Application crash via crafted encrypted message

EPSS

Процентиль: 41%
0.00195
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

CVSS3: 5.3
nvd
4 месяца назад

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

msrc
3 месяца назад

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

CVSS3: 5.3
debian
4 месяца назад

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext ...

CVSS3: 5.3
github
4 месяца назад

Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short

EPSS

Процентиль: 41%
0.00195
Низкий

5.3 Medium

CVSS3