AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.

Project Subscriptions

Vendors Products
Advanced Intrusion Detection Environment Project Subscribe
Advanced Intrusion Detection Environment Subscribe
Aide Project Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4272-1 aide security update
Debian DSA Debian DSA DSA-5977-1 aide security update
EUVD EUVD EUVD-2025-24863 AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
Ubuntu USN Ubuntu USN USN-7697-1 AIDE vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
References

Mon, 03 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
References

Wed, 20 Aug 2025 00:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 19 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Advanced Intrusion Detection Environment Project
Advanced Intrusion Detection Environment Project advanced Intrusion Detection Environment
CPEs cpe:2.3:a:advanced_intrusion_detection_environment_project:advanced_intrusion_detection_environment:*:*:*:*:*:*:*:*
Vendors & Products Advanced Intrusion Detection Environment Project
Advanced Intrusion Detection Environment Project advanced Intrusion Detection Environment

Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Aide Project
Aide Project aide
Vendors & Products Aide Project
Aide Project aide

Thu, 14 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 16:00:00 +0000

Type Values Removed Values Added
Description AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
Title AIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-04T21:12:46.467Z

Reserved: 2025-07-21T23:18:10.279Z

Link: CVE-2025-54409

cve-icon Vulnrichment

Updated: 2025-11-04T21:12:46.467Z

cve-icon NVD

Status : Modified

Published: 2025-08-14T16:15:39.397

Modified: 2025-11-04T22:16:28.043

Link: CVE-2025-54409

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-08-14T00:00:00Z

Links: CVE-2025-54409 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-08-16T21:41:09Z

Weaknesses