Description:
Libsodium before ad3004e, in atypical use cases involving certain custom
cryptography or untrusted data to crypto_core_ed25519_is_valid_point,
mishandles checks for whether an elliptic curve point is valid because
it sometimes allows points that aren't in the main cryptographic group.
(CVE-2025-69277)
- https://bugs.mageia.org/show_bug.cgi?id=34940
- https://lists.debian.org/debian-security-announce/2026/msg00002.html
- https://www.cve.org/CVERecord?id=CVE-2025-69277
- 9/core/sodium-1.0.18-3.1.mga9
Get the latest Linux and open source security news straight to your inbox.