Recutils: Recutils: Denial of Service due to divide-by-zero with empty password input
Published Dec 30, 2025
7.5
HIGHCVSS 3.1
EPSS 0.36%
Description
A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Service (DoS) via inputting an empty value as a password.
Affected products
Remediation
Red Hat statement
This vulnerability is rated Moderate for Red Hat. It allows attackers to cause a Denial of Service (DoS) by providing an empty password to the encryption/decryption routines of Recutils. This issue primarily affects community projects like Fedora 42 and Fedora 43, where Recutils is available.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jan 2, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.36% (0.00355) | 26.82th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.32% (0.00317) | 23.20th | v5 (v2026.06.15) |
| Dec 31, 2025 | 0.01% (0.00014) | 1.74th | v4 (v2025.03.14) |
References (8)
- http://ftp.gnu.org/gnu/recutils/ Product
- https://access.redhat.com/security/cve/CVE-2025-65409 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2426292 Issue Tracking
- https://github.com/MAXEUR5/Vulnerability_Disclosures/blob/main/2025/CVE-2025-65409.md exploitThird Party Advisory
- https://lists.gnu.org/archive/html/bug-recutils/2025-10/msg00004.html Mailing ListPatch
- https://nvd.nist.gov/vuln/detail/CVE-2025-65409
- https://www.cve.org/CVERecord?id=CVE-2025-65409
- https://www.gnu.org/software/recutils/ Product
| Link | Providers | Tags |
|---|---|---|
| http://ftp.gnu.org/gnu/recutils/ | Product | |
| https://access.redhat.com/security/cve/CVE-2025-65409 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2426292 | Issue Tracking | |
| https://github.com/MAXEUR5/Vulnerability_Disclosures/blob/main/2025/CVE-2025-65409.md | exploitThird Party Advisory | |
| https://lists.gnu.org/archive/html/bug-recutils/2025-10/msg00004.html | Mailing ListPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-65409 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-65409 | ||
| https://www.gnu.org/software/recutils/ | Product |
Change history (0)
No recorded changes yet.