CVE-2025-65409

Description

A flaw was found in Recutils. Attackers can exploit a divide-by-zero vulnerability in the encryption and decryption routines by providing an empty password. This can lead to a Denial of Service (DoS), making the application unavailable to legitimate users.

Statement

This vulnerability is rated Moderate for Red Hat. It allows attackers to cause a Denial of Service (DoS) by providing an empty password to the encryption/decryption routines of Recutils. This issue primarily affects community projects like Fedora 42 and Fedora 43, where Recutils is available.

Frequently Asked Questions

Want to get errata notifications? Sign up here.