AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
Metrics
Affected Vendors & Products
References
History
Sat, 16 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Aide Project
Aide Project aide |
|
Vendors & Products |
Aide Project
Aide Project aide |
Thu, 14 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 14 Aug 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems. | |
Title | AIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS) | |
Weaknesses | CWE-476 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-14T15:52:24.069Z
Updated: 2025-08-14T19:55:49.065Z
Reserved: 2025-07-21T23:18:10.279Z
Link: CVE-2025-54409

Updated: 2025-08-14T18:43:38.312Z

Status : Awaiting Analysis
Published: 2025-08-14T16:15:39.397
Modified: 2025-08-15T13:12:51.217
Link: CVE-2025-54409

No data.