CVE-2025-69277Patch

LOWCVSS 4.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 1 signal
  • Peaked 2d ago at 1 mentions (2026-02-13); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-13: 1Mentions · 2026-02-27: 1Mentions · 2026-04-30: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-02-13: 102-1302-2704-30
Signal classification1 categories
Patch
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • ThreatCluster@threatcluster
    Patch

    SUSE releases security fixes for libsodium and Zabbix, addressing crypto bypass, timing and access control flaws in CVE-2025-15444, CVE-2025-69277, CVE-2024-36469, CVE-2024-42325. #infosec https://threatcluster.io/cluster/suse-security-updates-address-multiple-cves-in-libsodium-and-35586bf0

    Post summary

    SUSE has issued security fixes for libsodium and Zabbix, addressing crypto bypass, timing, and access control flaws across several CVEs.

    0002084
    79 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    The PyNaCl vulnerability (CVE-2025-69277) just reminded us: cryptographic dependencies need constant attention. Here's a practical guide for openSUSE admins: check scripts, automation code, and AppArmor mitigations all included. Read more -> https://tinyurl.com/3pkzwaff #openSUSE https://t.co/DHaHuH7xZI

    Post summary

    The tweet announces CVE-2025-69277 and offers a practical guide with AppArmor mitigations for openSUSE admins, but does not provide a PoC, exploit code, or detailed technical specifics.

    00000744
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 URGENT: #SUSE Linux Security Update 🚨 Critical flaws (CVE-2025-15444, CVE-2025-69277) in the libsodium crypto library have been patched for SUSE Linux Micro 6.1. Read more: 👉 https://tinyurl.com/2ruz8nx4 #Security https://t.co/cNmawYYotA

    Post summary

    SUSE Linux Micro 6.1 has patched critical CVE-2025-15444 and CVE-2025-69277 in libsodium; no details on exploitation or PoC are provided.

    00000107
    1.3K followersView on X

Explore more