CVE-2025-47276

Source
https://cve.org/CVERecord?id=CVE-2025-47276
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47276.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-47276
Aliases
  • GHSA-v626-chv9-v9qr
Published
2025-05-13T15:34:28.801Z
Modified
2026-04-02T12:50:12.327141Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Actualizer Uses OpenSSL's "-passwd" Function Which Uses SHA512 Under The Hood Instead of Proper Password Hasher like Yescript/Argon2i
Details

Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating systems (OS). Prior to version 1.2.0, Actualizer uses OpenSSL's "-passwd" function, which uses SHA512 instead of a more suitable password hasher like Yescript/Argon2i. All Actualizer users building a full Debian Operating System are affected. Users should upgrade to version 1.2.0 of Actualizer. Existing OS deployment requires manual password changes against the alpha and root accounts. The change will deploy's Debian's yescript overriding the older SHA512 hash created by OpenSSL. As a workaround, users need to reset both root and "Alpha" users' passwords.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47276.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-328"
    ]
}
References

Affected packages

Git / github.com/chewkeanho/actualizer

Affected ranges

Type
GIT
Repo
https://github.com/chewkeanho/actualizer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.2.0"
        }
    ]
}

Affected versions

v1.*
v1.0.0
v1.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47276.json"

Git / github.com/chewkeanho/software-actualizer

Affected ranges

Type
GIT
Repo
https://github.com/chewkeanho/software-actualizer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/chewkeanho/software-actualizer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*
v1.0.0
v1.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47276.json"