Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v6x3-9r38-r27q | Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short |
Wed, 17 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Sequoia: Sequoia: Application crash via crafted encrypted message | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 15 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sequoia-pgp
Sequoia-pgp sequoia |
|
| Vendors & Products |
Sequoia-pgp
Sequoia-pgp sequoia |
Sun, 14 Dec 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. | |
| Weaknesses | CWE-195 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-15T21:29:01.140Z
Reserved: 2025-12-14T04:35:24.299Z
Link: CVE-2025-67897
Updated: 2025-12-15T21:28:55.651Z
Status : Deferred
Published: 2025-12-14T05:16:06.453
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-67897
OpenCVE Enrichment
Updated: 2025-12-15T14:06:07Z
Github GHSA