Improper Encoding or Escaping of Output in AIDE - CVE-2025-54389
Published: August 27, 2025
Vulnerability identifier: #VU114477
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54389
CWE-ID: CWE-116
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass detection rules.
The vulnerability exists due to improper input validation when handling file names. A remote attacker can pass a specially crafted file to the application and hide or remove the file from the logs or bypass AIDE detection of malicious files.
Affected software
AIDE
Debian Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
aide
aide (Red Hat package)
aide (Ubuntu package)
aide (Debian package)
aide-debuginfo
aide-debugsource
aide-help
aide-doc
OpenShift File Integrity Operator
Juniper Junos Space
Debian Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
aide
aide (Red Hat package)
aide (Ubuntu package)
aide (Debian package)
aide-debuginfo
aide-debugsource
aide-help
aide-doc
OpenShift File Integrity Operator
Juniper Junos Space
How to mitigate CVE-2025-54389
Install updates from vendor's website.
AIDE - update to 0.19.2
aide - addressed in versions 0.15.1-13, 0.16-103, 0.19.2-1
aide (Red Hat package) - addressed in versions 0.15.1-13.el7_9.5, 0.16-11.el8_2.2, 0.16-15.el8_6.1, 0.16-15.el8_8.1, 0.16-15.el8_10.2, 0.16-100.el9_0.1, 0.16-100.el9_2.1, 0.16-100.el9_4.1, 0.16-103.el9_6.2, 0.18.6-8.el10_0.2
aide (Ubuntu package) - addressed in versions 0.16~a2.git20130520-2ubuntu0.1+esm2, 0.16~a2.git20130520-3ubuntu0.1~esm2, 0.16.1-1ubuntu0.1+esm1, 0.16-3ubuntu0.1+esm1, 0.17.4-1ubuntu0.2, 0.18.6-2ubuntu0.1, 0.18.8-2ubuntu0.1
aide (Debian package) - addressed in versions 0.18.3-1+deb12u4, 0.19.1-2+deb13u1
aide - update to 0.18.6-7
aide-debuginfo - update to 0.18.6-7
aide-debugsource - update to 0.18.6-7
aide-help - update to 0.18.6-7
aide-doc - update to 0.19.2-1
OpenShift File Integrity Operator - update to 1.3.7
Juniper Junos Space - update to 26.1R1 Patch V1
aide - addressed in versions 0.15.1-13, 0.16-103, 0.19.2-1
aide (Red Hat package) - addressed in versions 0.15.1-13.el7_9.5, 0.16-11.el8_2.2, 0.16-15.el8_6.1, 0.16-15.el8_8.1, 0.16-15.el8_10.2, 0.16-100.el9_0.1, 0.16-100.el9_2.1, 0.16-100.el9_4.1, 0.16-103.el9_6.2, 0.18.6-8.el10_0.2
aide (Ubuntu package) - addressed in versions 0.16~a2.git20130520-2ubuntu0.1+esm2, 0.16~a2.git20130520-3ubuntu0.1~esm2, 0.16.1-1ubuntu0.1+esm1, 0.16-3ubuntu0.1+esm1, 0.17.4-1ubuntu0.2, 0.18.6-2ubuntu0.1, 0.18.8-2ubuntu0.1
aide (Debian package) - addressed in versions 0.18.3-1+deb12u4, 0.19.1-2+deb13u1
aide - update to 0.18.6-7
aide-debuginfo - update to 0.18.6-7
aide-debugsource - update to 0.18.6-7
aide-help - update to 0.18.6-7
aide-doc - update to 0.19.2-1
OpenShift File Integrity Operator - update to 1.3.7
Juniper Junos Space - update to 26.1R1 Patch V1
External References
Related Security Bulletins
- Multiple vulnerabilities in AIDE
- Debian update for aide
- Red Hat Enterprise Linux 9 update for aide
- Red Hat Enterprise Linux 8 update for aide
- Red Hat Enterprise Linux 10 update for aide
- Ubuntu update for aide
- Anolis OS update for aide
- Red Hat Enterprise Linux 8 update for aide
- Red Hat Enterprise Linux 8 update for aide
- Red Hat Enterprise Linux 9 update for aide
- Red Hat Enterprise Linux 9 update for aide
- Red Hat Enterprise Linux 8 update for aide
- Red Hat Enterprise Linux 9 update for aide
- openEuler 24.03 LTS update for aide
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for aide
- Anolis OS update for aide
- Multiple vulnerabilities in OpenShift File Integrity Operator
- Anolis OS update for aide
- Multiple vulnerabilities in Junos Space