Date: unknown
Location: lists.debian.org
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6094-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 05, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libsodium CVE ID : CVE-2025-69277 It was discovered that the crypto_core_ed25519_is_valid_point() function of the Sodium cryptography library mishandled checks for valid elliptic curve points. For the oldstable distribution (bookworm), this problem has been fixed in version 1.0.18-1+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 1.0.18-1+deb13u1. We recommend that you upgrade your libsodium packages. For the detailed security status of libsodium please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libsodium Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmlcELUACgkQEMKTtsN8 TjbfNBAAg6Xo1m3Huuza0EquwPDD+48pPH3Ba2EZ8kR3fFCwP5s6yWELFsv40nPO /kKg+u2shEc86Jttwa1qB8xLaymstpcIcaic+i2wkuUPyZkNMot4eg9B8e3Tn+TX VuZWq69+QgY6EEuYaYaofdgdlzsW7WmUj1LJgd39ipf75DClHIAUknf8Bh5vscUZ QSkrPZBtslmybQG/rhw6qvukxqF5X79TrI8Yq/GDhnMcWciraRAmUWsHMre/D1+9 8IuK+90avLIwJSYp1Z0WuUKXP2CuWuMabnA4mxoyxDu+f+C8+yLhq/89xdBufWku EXUYCDlUMKRncp6NarXa8oBx8brjYsJZZIhg7KapArRyXNpJq4S0fneg1NLlAY3X Kp9EkgZGcPCO4eF3vuHJbIFUpvgOezVjp5E9kJdIAOw4h8XN2JRyM5A9m/FExc44 yKfUMj6ppEBhyUeWMIpQSMUHpu6cjXMKDzzYLcQxNbhKbfO4oCEkzIg/gDZkaXdi OC9DlLXUV5bNYrNEMB1nciWk2GVcWcAEavnbaLst5ZMVuye4katsinoxb/5JxvGq 1ZpvMnbAku0HpMYmxkBiIt8LHYKAMuIZxIk2JJW8ZqezpZQP1EfKMReZAtSqL68E Q1E9ky/EEje6n8PP3C2EFliS4knSLU+OBui2RoxdiW3nmRaPPZ4= =bmE1 -----END PGP SIGNATURE-----