Vulnerability Description
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://bugs.debian.org/1122582
- https://gitlab.com/sequoia-pgp/sequoia/-/blob/b59886e5e7bdf7169ed330f309a6633d13
- https://gitlab.com/sequoia-pgp/sequoia/-/commit/b59886e5e7bdf7169ed330f309a6633d
FAQ
What is CVE-2025-67897?
CVE-2025-67897 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted mes...
How severe is CVE-2025-67897?
CVE-2025-67897 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67897?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.