AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
History

Wed, 20 Aug 2025 00:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 19 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Advanced Intrusion Detection Environment Project
Advanced Intrusion Detection Environment Project advanced Intrusion Detection Environment
CPEs cpe:2.3:a:advanced_intrusion_detection_environment_project:advanced_intrusion_detection_environment:*:*:*:*:*:*:*:*
Vendors & Products Advanced Intrusion Detection Environment Project
Advanced Intrusion Detection Environment Project advanced Intrusion Detection Environment

Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Aide Project
Aide Project aide
Vendors & Products Aide Project
Aide Project aide

Thu, 14 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 16:00:00 +0000

Type Values Removed Values Added
Description AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
Title AIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-14T15:52:24.069Z

Updated: 2025-08-14T19:55:49.065Z

Reserved: 2025-07-21T23:18:10.279Z

Link: CVE-2025-54409

cve-icon Vulnrichment

Updated: 2025-08-14T18:43:38.312Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-14T16:15:39.397

Modified: 2025-08-19T19:11:40.850

Link: CVE-2025-54409

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-08-14T00:00:00Z

Links: CVE-2025-54409 - Bugzilla