CVE-2025-65409: Divide by Zero
Published Dec 30, 2025
·Updated
A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Service (DoS) via inputting an empty value as a password.
Affected Software
2 affected components
GNU recutils
GNU recutils=1.9
Remediation
Event History
Dec 30, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65409?
CVE-2025-65409 has a severity rating that indicates it can lead to Denial of Service (DoS) conditions.
2
How do I fix CVE-2025-65409?
To fix CVE-2025-65409, update to the latest version of GNU Recutils that addresses this vulnerability.
3
What versions of GNU Recutils are affected by CVE-2025-65409?
CVE-2025-65409 affects GNU Recutils version 1.9 and earlier.
4
What kind of attack does CVE-2025-65409 enable?
CVE-2025-65409 allows attackers to perform a Denial of Service (DoS) by inputting an empty password.
5
Is CVE-2025-65409 a local or remote vulnerability?
CVE-2025-65409 can be exploited remotely, allowing attackers to cause a DoS from various locations.