CVE Vulnerabilities

CVE-2025-54409

NULL Pointer Dereference

Published: Aug 14, 2025 | Modified: Aug 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Aide Ubuntu devel *
Aide Ubuntu esm-infra-legacy/trusty *
Aide Ubuntu esm-infra/bionic *
Aide Ubuntu esm-infra/focal *
Aide Ubuntu esm-infra/xenial *
Aide Ubuntu jammy *
Aide Ubuntu noble *
Aide Ubuntu plucky *
Aide Ubuntu upstream *

Potential Mitigations

References