CVE-2025-67897

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.
Configurations

No configuration.

History

14 Dec 2025, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-14 05:16

Updated : 2025-12-15 18:22


NVD link : CVE-2025-67897

Mitre link : CVE-2025-67897

CVE.ORG link : CVE-2025-67897


JSON object : View

Products Affected

No product.

CWE
CWE-195

Signed to Unsigned Conversion Error