Cryptographic issues in circl - CVE-2025-8556
Published: November 14, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise session security.
The vulnerability exists due to an error in FourQ elliptic curve implementation and incorrect point validation during Diffie-Hellman key exchange. A remote attacker can compromise session security via low-order point injection and gain access to sensitive information.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
HPC Module
openSUSE Leap
Fedora
Astronomer with IBM
Netcool Operations Insight
Splunk Enterprise
libsquashfuse0
squashfuse-debugsource
libsquashfuse0-debuginfo
squashfuse
squashfuse-debuginfo
squashfuse-tools-debuginfo
squashfuse-devel
squashfuse-tools
apptainer-sle15_7
apptainer-leap
apptainer-sle15_6
apptainer-sle16
apptainer-debuginfo
apptainer
gopass-jsonapi
How to mitigate CVE-2025-8556
Astronomer with IBM - update to 1.1.0
Netcool Operations Insight - update to 1.6.15
Splunk Enterprise - addressed in versions 9.3.10, 9.4.9, 10.0.4, 10.2.1
libsquashfuse0 - update to 0.5.0-150600.3.2.1
squashfuse-debugsource - update to 0.5.0-150600.3.2.1
libsquashfuse0-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse - update to 0.5.0-150600.3.2.1
squashfuse-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-tools-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-devel - update to 0.5.0-150600.3.2.1
squashfuse-tools - update to 0.5.0-150600.3.2.1
apptainer-sle15_7 - update to 1.4.5-150600.4.12.1
apptainer-leap - update to 1.4.5-150600.4.12.1
apptainer-sle15_6 - update to 1.4.5-150600.4.12.1
apptainer-sle16 - update to 1.4.5-150600.4.12.1
apptainer-debuginfo - update to 1.4.5-150600.4.12.1
apptainer - update to 1.4.5-150600.4.12.1
gopass-jsonapi - update to 1.16.0-1.fc43
External References
- https://access.redhat.com/security/cve/CVE-2025-8556
- https://bugzilla.redhat.com/show_bug.cgi?id=2371624
- https://github.com/cloudflare/circl/security/advisories/GHSA-2x5j-vhc8-9cwm
- https://github.com/cloudflare/circl/tree/v1.6.1
- https://news.ycombinator.com/item?id=45669593
- https://www.botanica.software/blog/cryptographic-issues-in-cloudflares-circl-fourq-implementation