CVE-2025-54409 Details
Description
AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
A null pointer dereference vulnerability has been identified in AIDE (Advanced Intrusion Detection Environment) versions 0.13 prior to 0.19.1. This vulnerability allows a local user to cause a denial-of-service by crashing the program during report printing or database listing. The issue arises when extended file attributes are set with an empty value or a key containing a comma. The vulnerability has been patched in AIDE version 0.19.2.
Users are advised to upgrade to AIDE version 0.19.2. If an upgrade is not possible, consider removing the 'xattrs' group from rules matching files on affected file systems.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aide/aide/security/advisories/GHSA-79g7-f8rv-jcxh | CISA-ADP | ExploitMitigationVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2025/08/msg00011.html | CVE | |
| http://www.openwall.com/lists/oss-security/2025/08/14/8 | CVE | |
| https://github.com/aide/aide/commit/54a6d0d9d5f14b81961d66373c0291bf4af4135a | [email protected] | Patch |
| https://github.com/aide/aide/releases/tag/v0.19.2 | [email protected] | Release Notes |
| https://github.com/aide/aide/security/advisories/GHSA-79g7-f8rv-jcxh | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| advanced intrusion detection environment project advanced intrusion detection environment | >= 0.13, < 0.19.2 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 19, 2025 | Initial Analysis | [email protected] |
| Aug 14, 2025 | CVE Modified | CISA-ADP |
| Aug 14, 2025 | New CVE Received | [email protected] |