vulnerability
Ubuntu: USN-7949-1 (CVE-2025-69277): Sodium vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 3 | (AV:L/AC:M/Au:N/C:P/I:P/A:N) | Dec 31, 2025 | Jan 9, 2026 | Jan 12, 2026 |
Severity
3
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:N)
Published
Dec 31, 2025
Added
Jan 9, 2026
Modified
Jan 12, 2026
Description
It was discovered that Sodium incorrectly handled the elliptic curve point
validity check in certain atypical use cases. This could result in invalid
points being used, contrary to expectations.
Solution
ubuntu-upgrade-libsodium23
References
- CVE-2025-69277
- https://attackerkb.com/topics/CVE-2025-69277
- CWE-184
- UBUNTU-USN-7949-1
- URL-https://00f.net/2025/12/30/libsodium-vulnerability/
- URL-https://ianix.com/pub/ed25519-deployment.html
- URL-https://news.ycombinator.com/item?id=46435614
- URL-https://ubuntu.com/security/notices/USN-7949-1
- URL-https://www.cve.org/CVERecord?id=CVE-2025-69277
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.