Logo
vulnerabilityCVE-2025-69277
Name
CVE-2025-69277
Source
NVD ( link)Debian ( link)
Description
libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libsodium
Patched

Vulnerability Ratings#


4.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
1.0.18
Patched
yocto
master
1.0.22
Not Affected

Resolved with patches#


libsodium (yocto:kirkstone)

#
Title
Author
Resolve
1
core_ed25519_is_valid_point: check Y==Z in addition to X==0
Frank Denis <github@pureftpd.org>
CVE-2025-69277

libsodium (yocto:scarthgap)

#
Title
Author
Resolve
1
core_ed25519_is_valid_point: check Y==Z in addition to X==0
Frank Denis <github@pureftpd.org>
CVE-2025-69277