Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:0482-1

Опубликовано: 12 фев. 2026
Источник: suse-cvrf

Описание

Security update for libsodium

This update for libsodium fixes the following issues:

  • CVE-2025-15444: Fixed cryptographic bypass via improper elliptic curve point validation (bsc#1256070).
  • CVE-2025-69277: Fixed incorrect validation of elliptic curve points in crypto_core_ed25519_is_valid_point function (bsc#1255764).

Список пакетов

SUSE Linux Enterprise Module for Public Cloud 12
libsodium23-1.0.16-1.15.1

Описание

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277 https://www.cve.org/CVERecord?id=CVE-2025-69277 . The libsodium vulnerability states: In atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. 0.000042 includes a version of libsodium updated to 1.0.20-stable, released January 3, 2026, which includes a fix for the vulnerability.


Затронутые продукты
SUSE Linux Enterprise Module for Public Cloud 12:libsodium23-1.0.16-1.15.1

Ссылки

Описание

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.


Затронутые продукты
SUSE Linux Enterprise Module for Public Cloud 12:libsodium23-1.0.16-1.15.1

Ссылки