Advisories ยป MGASA-2026-0004

Updated sodium packages fix security vulnerability

Publication date: 10 Jan 2026
Modification date: 10 Jan 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-69277

Description

Libsodium before ad3004e, in atypical use cases involving certain custom
cryptography or untrusted data to crypto_core_ed25519_is_valid_point,
mishandles checks for whether an elliptic curve point is valid because
it sometimes allows points that aren't in the main cryptographic group.
(CVE-2025-69277)
                

References

SRPMS

9/core