Back

HIGH

Recutils: Recutils: Denial of Service due to divide-by-zero with empty password input

Published Dec 30, 2025

Description

A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Service (DoS) via inputting an empty value as a password.

Affected products

Remediation

Red Hat statement

This vulnerability is rated Moderate for Red Hat. It allows attackers to cause a Denial of Service (DoS) by providing an empty password to the encryption/decryption routines of Recutils. This issue primarily affects community projects like Fedora 42 and Fedora 43, where Recutils is available.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 30, 2025
Updated Jan 2, 2026
Reserved Nov 18, 2025
CISA Vulnrichment
Updated Jan 2, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 30, 2025