Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-69277

Опубликовано: 31 дек. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.5

Описание

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

РелизСтатусПримечание
devel

not-affected

1.0.18-2
esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

esm-infra/xenial

needs-triage

jammy

released

1.0.18-1ubuntu0.22.04.1
noble

released

1.0.18-1ubuntu0.24.04.1
plucky

released

1.0.18-1ubuntu0.25.04.1
questing

released

1.0.18-1ubuntu0.25.10.1
upstream

released

1.0.18-2

Показывать по

EPSS

Процентиль: 5%
0.00021
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
nvd
около 1 месяца назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

msrc
около 1 месяца назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

CVSS3: 4.5
debian
около 1 месяца назад

libsodium before ad3004e, in atypical use cases involving certain cust ...

CVSS3: 4.5
github
около 1 месяца назад

libsodium has Incomplete List of Disallowed Inputs

suse-cvrf
4 дня назад

Security update for libsodium

EPSS

Процентиль: 5%
0.00021
Низкий

4.5 Medium

CVSS3