CVE-2025-54409

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-54409
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-54409.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-54409
Downstream
Related
  • GHSA-79g7-f8rv-jcxh
Published
2025-08-14T16:15:39Z
Modified
2025-08-19T20:46:01.773430Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.

References

Affected packages

Debian:11 / aide

Package

Name
aide
Purl
pkg:deb/debian/aide?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.17.3-4+deb11u3

Affected versions

0.*

0.17.3-4
0.17.3-4+deb11u1
0.17.3-4+deb11u2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / aide

Package

Name
aide
Purl
pkg:deb/debian/aide?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.18.3-1+deb12u4

Affected versions

0.*

0.18.3-1
0.18.3-1+deb12u1
0.18.3-1+deb12u2
0.18.3-1+deb12u3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / aide

Package

Name
aide
Purl
pkg:deb/debian/aide?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.19.1-2+deb13u1

Affected versions

0.*

0.19.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / aide

Package

Name
aide
Purl
pkg:deb/debian/aide?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.19.2-1

Affected versions

0.*

0.19.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/aide/aide

Affected ranges

Type
GIT
Repo
https://github.com/aide/aide
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

aide.*

aide.0.10.release
aide.0.11.rc1.release
aide.0.11.rc2.release
aide.0.11.rc3.release
aide.0.11.release
aide.0.11a.debian
aide.0.11b.nocurl
aide.0.12.rc1.release
aide.0.12.rc2.release
aide.0.12.release
aide.0.13.1.release
aide.0.13.rc1.release
aide.0.13.rc2.release
aide.0.13.release
aide.0.14.1.release
aide.0.14.2.release
aide.0.14.rc1.release
aide.0.14.rc2.release
aide.0.14.rc3.release
aide.0.14.release
aide.0.15.1.release
aide.0.15.rc1.release
aide.0.15.release

cs.*

cs.tut.fi.import

v0.*

v0.16
v0.16.1
v0.16.2
v0.16a1
v0.16a2
v0.16b1
v0.16rc1
v0.17
v0.17.1
v0.17.2
v0.17.3
v0.18
v0.19
v0.19.1