CVE-2025-49506

NameCVE-2025-49506
DescriptionAPR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6437-1
Debian Bugs1143837

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apr-util (PTS)bullseye (security), bullseye1.6.1-5+deb11u1vulnerable
bookworm1.6.3-1vulnerable
trixie1.6.3-3vulnerable
trixie (security)1.6.3-3+deb13u1fixed
forky, sid1.6.4-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apr-utilsourcetrixie1.6.3-3+deb13u1DSA-6437-1
apr-utilsource(unstable)1.6.4-11143837

Notes

https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5
Fixed by: https://github.com/apache/apr-util/commit/f77a20761cb15686f8d4de5b5eafc534ae24b19e (1.6.4-rc1-candidate)

Search for package or bug name: Reporting problems