CVE-2025-54409
AIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
Rajesh Pangare discovered two vulnerabilities in aide, an advanced intrusion detection system. A local attacker can take advantage of these flaws to hide the addition or removal of a file from the the report, tamper with the log output, or cause aide to crash during report printing or database listing. For the oldstable distribution (bookworm), these problems have been fixed in version 0.18.3-1+deb12u4. For the stable distribution (trixie), these problems have been fixed in version 0.19.1-2+deb13u1.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-07-21 CVE Reserved
- 2025-08-14 CVE Published
- 2025-08-14 CVE Updated
- 2025-08-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-476: NULL Pointer Dereference
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/aide/aide/security/advisories/GHSA-79g7-f8rv-jcxh | X_refsource_confirm | |
https://github.com/aide/aide/commit/54a6d0d9d5f14b81961d66373c0291bf4af4135a | X_refsource_misc | |
https://github.com/aide/aide/releases/tag/v0.19.2 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Aide Search vendor "Aide" | Aide Search vendor "Aide" for product "Aide" | >= 0.13.0 < 0.19.2 Search vendor "Aide" for product "Aide" and version " >= 0.13.0 < 0.19.2" | en |
Affected
|