MGASA-2026-0004 - Updated sodium packages fix security vulnerability. MGASA-2026-0004 - Updated sodium packages fix security vulnerability Publication date: 10 Jan 2026 URL: https://advisories.mageia.org/MGASA-2026-0004.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-69277 Description: Libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. (CVE-2025-69277) References: - https://bugs.mageia.org/show_bug.cgi?id=34940 - https://lists.debian.org/debian-security-announce/2026/msg00002.html - https://www.cve.org/CVERecord?id=CVE-2025-69277 SRPMS: - 9/core/sodium-1.0.18-3.1.mga9 . Updated sodium packages in Mageia address a critical issue affecting cryptography practices. Immediate action recommended.. Mageia Sodium Packages, Security Vulnerabilities, Cryptography Issues. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.