CVE-2025-54409

AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
Configurations

Configuration 1 (hide)

cpe:2.3:a:advanced_intrusion_detection_environment_project:advanced_intrusion_detection_environment:*:*:*:*:*:*:*:*

History

19 Aug 2025, 19:11

Type Values Removed Values Added
CPE cpe:2.3:a:advanced_intrusion_detection_environment_project:advanced_intrusion_detection_environment:*:*:*:*:*:*:*:*
First Time Advanced Intrusion Detection Environment Project advanced Intrusion Detection Environment
Advanced Intrusion Detection Environment Project
Summary
  • (es) AIDE es un entorno avanzado de detección de intrusiones. Desde la versión 0.13 hasta la 0.19.1, existe una vulnerabilidad de desreferencia de puntero nulo en AIDE. Un atacante puede bloquear el programa durante la impresión de informes o el listado de bases de datos tras configurar atributos de archivo extendidos con un valor de atributo vacío o con una clave que contenga una coma. Un usuario local podría explotar esto para provocar una denegación de servicio local. Este problema se ha corregido en la versión 0.19.2. Una solución alternativa consiste en eliminar el grupo xattrs de las reglas que coinciden con los archivos de los sistemas de archivos afectados.
References () https://github.com/aide/aide/commit/54a6d0d9d5f14b81961d66373c0291bf4af4135a - () https://github.com/aide/aide/commit/54a6d0d9d5f14b81961d66373c0291bf4af4135a - Patch
References () https://github.com/aide/aide/releases/tag/v0.19.2 - () https://github.com/aide/aide/releases/tag/v0.19.2 - Release Notes
References () https://github.com/aide/aide/security/advisories/GHSA-79g7-f8rv-jcxh - () https://github.com/aide/aide/security/advisories/GHSA-79g7-f8rv-jcxh - Exploit, Vendor Advisory, Mitigation

14 Aug 2025, 20:15

Type Values Removed Values Added
References () https://github.com/aide/aide/security/advisories/GHSA-79g7-f8rv-jcxh - () https://github.com/aide/aide/security/advisories/GHSA-79g7-f8rv-jcxh -

14 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-14 16:15

Updated : 2025-08-19 19:11


NVD link : CVE-2025-54409

Mitre link : CVE-2025-54409

CVE.ORG link : CVE-2025-54409


JSON object : View

Products Affected

advanced_intrusion_detection_environment_project

  • advanced_intrusion_detection_environment
CWE
CWE-476

NULL Pointer Dereference