rpm package
suse/libsodium&distro=SUSE Linux Enterprise Module for Basesystem 15 SP7
pkg:rpm/suse/libsodium&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-15444 | — | < 1.0.18-150000.4.11.1 | 1.0.18-150000.4.11.1 | Jan 6, 2026 | Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277 https://www.cve.org/CVERecord?id=CVE-20 | ||
| CVE-2025-69277 | Med | 4.5 | < 1.0.18-150000.4.14.1 | 1.0.18-150000.4.14.1 | Dec 31, 2025 | libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic g |
- CVE-2025-15444Jan 6, 2026affected < 1.0.18-150000.4.11.1fixed 1.0.18-150000.4.11.1
Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277 https://www.cve.org/CVERecord?id=CVE-20
- affected < 1.0.18-150000.4.14.1fixed 1.0.18-150000.4.14.1
libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic g