AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-476"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54409.json"
}{
"cpe": "cpe:2.3:a:advanced_intrusion_detection_environment_project:advanced_intrusion_detection_environment:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0.13"
},
{
"fixed": "0.19.2"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54409.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "139957638231509996529344293125411944926",
"length": 597
},
"id": "CVE-2025-54409-063f70e3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aide/aide/commit/54a6d0d9d5f14b81961d66373c0291bf4af4135a",
"target": {
"file": "src/db_file.c",
"function": "str_xattr"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"240633656327470416087605333886147545107",
"222532754395668194269031825964900562400",
"99177587292487885968028833533206935792",
"67638161372897658726778897554014937801"
],
"threshold": 0.9
},
"id": "CVE-2025-54409-0d77ac33",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aide/aide/commit/54a6d0d9d5f14b81961d66373c0291bf4af4135a",
"target": {
"file": "src/db_file.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "334746699140210284191954817973846700488",
"length": 5275
},
"id": "CVE-2025-54409-1284eacd",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aide/aide/commit/54a6d0d9d5f14b81961d66373c0291bf4af4135a",
"target": {
"file": "src/db.c",
"function": "db_char2line"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"118297189687823352206657114831738145911",
"80277695535089239552610719086309280993",
"9520165563721108839015907472576524260",
"233545489577789070350457659198852240444",
"236718370463409669901992631373774490209",
"230224585779926504478593569389342944878",
"302374927479932083730091917067714381459",
"310035386697265496613305999705883865383",
"229728355393457239767922114854516406444",
"161099081258952239597598758032348639520",
"220630822962340560947005124271742234211",
"136705913406198808329408834090435255767",
"47663340844430266454309999591453196185"
],
"threshold": 0.9
},
"id": "CVE-2025-54409-1fbc0f1e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aide/aide/commit/54a6d0d9d5f14b81961d66373c0291bf4af4135a",
"target": {
"file": "src/db.c"
}
}
]
"2026-08-12T15:16:42Z"