CVE-2025-69277

NameCVE-2025-69277
Descriptionlibsodium before ad3004e, in atypical use cases involving certain cust ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1124375

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libsodium (PTS)forky, bookworm, bullseye, trixie1.0.18-1vulnerable
sid1.0.18-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libsodiumsource(unstable)(unfixed)1124375

Notes

https://00f.net/2025/12/30/libsodium-vulnerability/
Fixed by: https://github.com/jedisct1/libsodium/commit/ad3004ec8731730e93fcfbbc824e67eadc1c1bae

Search for package or bug name: Reporting problems