AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade aideUpgrade aide-debuginfo | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade aideUpgrade aide-debuginfoUpgrade aide-debugsource | Mar 9, 2026 | Aug 14, 2025 |
| Debian | — | Upgrade aide | Aug 18, 2025 | Aug 18, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade aide | Nov 12, 2025 | Nov 6, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade aide | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade aide | Nov 12, 2025 | Nov 6, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade aide | Nov 21, 2025 | Nov 6, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Aug 14, 2025 |
| Ubuntu | — | Upgrade aide (Ubuntu Pro)Upgrade aide | Aug 18, 2025 | Aug 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub