ELA-1631-1 libsodium security update

cryptographic validation bypass

2026-02-01
Packagelibsodium
Version1.0.17-1+deb10u1 (buster)
Related CVEs CVE-2025-69277


It was discovered that the crypto_core_ed25519_is_valid_point() function of the Sodium cryptography library mishandled checks for valid elliptic curve points.



For Debian 10 buster, these problems have been fixed in version 1.0.17-1+deb10u1.

We recommend that you upgrade your libsodium packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.