Vulnerability CVE-2025-69277: Information

Description

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

Severity: MEDIUM (4.5)
Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Published: Dec. 31, 2025
Modified: Jan. 7, 2026
Error type identifier: CWE-184

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libsodiumsisyphus1.0.21-alt11.0.21-alt1ALT-PU-2026-1083-2404542Fixed
libsodiumsisyphus_riscv641.0.21-alt11.0.21-alt1ALT-PU-2026-1122-1-Fixed
libsodiumsisyphus_loongarch641.0.21-alt11.0.21-alt1ALT-PU-2026-1127-1-Fixed
libsodiump101.0.18-alt31.0.18-alt3ALT-PU-2026-1010-2404262Fixed
libsodiump10_e2k1.0.18-alt31.0.18-alt3ALT-PU-2026-1613-1-Fixed
libsodiumc10f21.0.18-alt31.0.18-alt3ALT-PU-2026-1012-2404263Fixed
libsodiumc9f21.0.18-alt31.0.18-alt3ALT-PU-2026-1014-2404264Fixed
libsodiump111.0.21-alt11.0.21-alt1ALT-PU-2026-1093-2404559Fixed

References to Advisories, Solutions, and Tools