CVE-2025-69277

Published: January 7, 2026Last modified: January 15, 2026

Description

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

Severity score breakdown

ParameterValue
Base score4.5
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibsodiumFixed (1.0.18-r3)
25 LTSlibsodiumFixed (1.0.20-r1)
StreamlibsodiumFixed (1.0.20-r1)

References

ON THIS PAGE