Security update for libsodium
This security update for libsodium addresses cryptographic bypass vulnerabilities related to improper elliptic curve point validation. The update fixes CVE-2025-15444 and CVE-2025-69277, which involve incorrect validation of elliptic curve points in the crypto_core_ed25519_is_valid_point function. Additional improvements include new cryptographic functions, performance enhancements, and security hardening against side-channel attacks and speculative execution. No affected versions are explicitly stated.
AI Analysis
Technical Summary
The libsodium update fixes two security issues: CVE-2025-15444, a cryptographic bypass caused by improper elliptic curve point validation, and CVE-2025-69277, which involves incorrect validation of elliptic curve points in the crypto_core_ed25519_is_valid_point function when handling custom cryptography or untrusted data. The update also introduces new functions for secure IP address encryption and anonymization, improves performance on ARM platforms, and adds mitigations against compiler-induced side channels and speculative execution attacks. The crypto_core_ed25519_is_valid_point function now properly rejects small-order points not in the main subgroup, enhancing cryptographic validation.
Potential Impact
These vulnerabilities could allow cryptographic bypasses due to improper validation of elliptic curve points, potentially weakening the security guarantees of cryptographic operations relying on libsodium. The impact is medium severity as per the provided data. No known exploits are reported in the wild.
Mitigation Recommendations
A security update to libsodium including these fixes is available. Users should update to the fixed version (1.0.21) or later to address these vulnerabilities. No additional mitigation steps are indicated beyond applying the update.
Security update for libsodium
Description
This security update for libsodium addresses cryptographic bypass vulnerabilities related to improper elliptic curve point validation. The update fixes CVE-2025-15444 and CVE-2025-69277, which involve incorrect validation of elliptic curve points in the crypto_core_ed25519_is_valid_point function. Additional improvements include new cryptographic functions, performance enhancements, and security hardening against side-channel attacks and speculative execution. No affected versions are explicitly stated.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The libsodium update fixes two security issues: CVE-2025-15444, a cryptographic bypass caused by improper elliptic curve point validation, and CVE-2025-69277, which involves incorrect validation of elliptic curve points in the crypto_core_ed25519_is_valid_point function when handling custom cryptography or untrusted data. The update also introduces new functions for secure IP address encryption and anonymization, improves performance on ARM platforms, and adds mitigations against compiler-induced side channels and speculative execution attacks. The crypto_core_ed25519_is_valid_point function now properly rejects small-order points not in the main subgroup, enhancing cryptographic validation.
Potential Impact
These vulnerabilities could allow cryptographic bypasses due to improper validation of elliptic curve points, potentially weakening the security guarantees of cryptographic operations relying on libsodium. The impact is medium severity as per the provided data. No known exploits are reported in the wild.
Mitigation Recommendations
A security update to libsodium including these fixes is available. Users should update to the fixed version (1.0.21) or later to address these vulnerabilities. No additional mitigation steps are indicated beyond applying the update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:20642-1
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-69277"]
- State
- PUBLISHED
Threat ID: 6aab498955bf5e2cf5990f09
Added to database: 09/17/2026, 01:59:37 UTC
Last enriched: 09/17/2026, 02:27:18 UTC
Last updated: 09/17/2026, 04:01:24 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.