Updated sodium packages fix security vulnerability
Publication date: 10 Jan 2026Modification date: 10 Jan 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-69277
Description
Libsodium before ad3004e, in atypical use cases involving certain custom
cryptography or untrusted data to crypto_core_ed25519_is_valid_point,
mishandles checks for whether an elliptic curve point is valid because
it sometimes allows points that aren't in the main cryptographic group.
(CVE-2025-69277)
References
SRPMS
9/core
- sodium-1.0.18-3.1.mga9