CVE Vulnerabilities

CVE-2025-69277

Incomplete List of Disallowed Inputs

Published: Dec 31, 2025 | Modified: Jan 07, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.5 MODERATE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that arent in the main cryptographic group.

Weakness

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Affected Software

NameVendorStart VersionEnd Version
LibsodiumUbuntujammy*
LibsodiumUbuntunoble*
LibsodiumUbuntuplucky*
LibsodiumUbuntuquesting*
LibsodiumUbuntuupstream*

Potential Mitigations

References