CVE-2025-54409: AIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS)
AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54409?
CVE-2025-54409 is classified as a high severity vulnerability due to the potential for an attacker to crash the AIDE application.
How do I fix CVE-2025-54409?
To address CVE-2025-54409, upgrade AIDE to version 0.19.2 or later, which resolves the null pointer dereference issue.
What versions of AIDE are affected by CVE-2025-54409?
CVE-2025-54409 affects AIDE versions from 0.13 to 0.19.1, inclusive.
What type of vulnerability is CVE-2025-54409?
CVE-2025-54409 is a null pointer dereference vulnerability that can lead to application crashes.
Can I exploit CVE-2025-54409 remotely?
Yes, an attacker can exploit CVE-2025-54409 remotely if they manipulate the extended file attributes.