{"id":"openSUSE-SU-2026:20642-1","summary":"Security update for libsodium","details":"This update for libsodium fixes the following issues:\n\nSecurity fixes:\n\n- CVE-2025-15444: Cryptographic bypass via improper elliptic curve point validation (bsc#1256070).\n- CVE-2025-69277: incorrect validation of elliptic curve points certain custom cryptography or untrusted data to\n  crypto_core_ed25519_is_valid_point function (bsc#1255764).\n\nOther fixes:\n\n- Update to 1.0.21\n * The new crypto_ipcrypt_* functions implement mechanisms for securely\n encrypting and anonymizing IP addresses.\n * The sodium_bin2ip and sodium_ip2bin helper functions have been added to\n complement the crypto_ipcrypt_* functions and easily convert addresses\n between bytes and strings.\n * XOF: the crypto_xof_shake* and crypto_xof_turboshake* functions are\n * standard\n extendable output functions. From input of any length, they can derive\n output of any length with the same properties as hash functions. These\n primitives are required by many post-quantum mechanisms, but can also be\n used for a wide range of applications, including key derivation, session\n encryption and more.\n * Performance of AES256-GCM and AEGIS on ARM has been improved with some\n compilers\n * Security: optblockers have been introduced in critical code paths to prevent\n compilers from introducing unwanted side channels via conditional jumps. This\n was observed on RISC-V targets with specific compilers and options.\n * Security: crypto_core_ed25519_is_valid_point() now properly rejects\n small-order points that are not in the main subgroup\n * ((nonnull)) attributes have been relaxed on some crypto_stream* functions to\n allow NULL output buffers when the output length is zero\n * A cross-compilation issue with old clang versions has been fixed\n * crypto_aead_aes256gcm_is_available is exported to JavaScript\n * Security: memory fences have been added after MAC verification in AEAD to\n prevent speculative access to plaintext before authentication is complete\n * Assembly files now include .gnu.property notes for proper IBT and Shadow\n Stack support when building with CET instrumentation.\n","modified":"2026-05-01T18:29:50.323762Z","published":"2026-04-28T15:27:57Z","related":["CVE-2025-15444","CVE-2025-69277"],"upstream":["CVE-2025-15444","CVE-2025-69277"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255764"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256070"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-15444"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-69277"}],"schema_version":"1.7.5"}