Cryptographic issues in circl - CVE-2025-8556

 

Cryptographic issues in circl - CVE-2025-8556

Published: November 14, 2025


Vulnerability identifier: #VU118530
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-8556
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise session security.

The vulnerability exists due to an error in FourQ elliptic curve implementation and incorrect point validation during Diffie-Hellman key exchange. A remote attacker can compromise session security via low-order point injection and gain access to sensitive information. 


Affected software

circl
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
HPC Module
openSUSE Leap
Fedora
Astronomer with IBM
Netcool Operations Insight
Splunk Enterprise
libsquashfuse0
squashfuse-debugsource
libsquashfuse0-debuginfo
squashfuse
squashfuse-debuginfo
squashfuse-tools-debuginfo
squashfuse-devel
squashfuse-tools
apptainer-sle15_7
apptainer-leap
apptainer-sle15_6
apptainer-sle16
apptainer-debuginfo
apptainer
gopass-jsonapi

How to mitigate CVE-2025-8556

Install updates from vendor's website.

circl - update to 1.6.1
Astronomer with IBM - update to 1.1.0
Netcool Operations Insight - update to 1.6.15
Splunk Enterprise - addressed in versions 9.3.10, 9.4.9, 10.0.4, 10.2.1
libsquashfuse0 - update to 0.5.0-150600.3.2.1
squashfuse-debugsource - update to 0.5.0-150600.3.2.1
libsquashfuse0-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse - update to 0.5.0-150600.3.2.1
squashfuse-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-tools-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-devel - update to 0.5.0-150600.3.2.1
squashfuse-tools - update to 0.5.0-150600.3.2.1
apptainer-sle15_7 - update to 1.4.5-150600.4.12.1
apptainer-leap - update to 1.4.5-150600.4.12.1
apptainer-sle15_6 - update to 1.4.5-150600.4.12.1
apptainer-sle16 - update to 1.4.5-150600.4.12.1
apptainer-debuginfo - update to 1.4.5-150600.4.12.1
apptainer - update to 1.4.5-150600.4.12.1
gopass-jsonapi - update to 1.16.0-1.fc43

External References

Related Security Bulletins