CVE-2025-66270

Source
https://cve.org/CVERecord?id=CVE-2025-66270
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66270.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66270
Downstream
Related
Published
2025-12-05T00:00:00Z
Modified
2026-07-22T04:02:49.437917Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.

Database specific
{
    "cna_assigner": "mitre",
    "cwe_ids": [
        "CWE-290"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66270.json"
}
References

Affected packages

Git / github.com/andyholmes/valent

Affected ranges

Type
GIT
Repo
https://github.com/andyholmes/valent
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.0.0.alpha.49"
        }
    ]
}
Type
GIT
Repo
https://github.com/gsconnect/gnome-shell-extension-gsconnect
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "68"
        }
    ]
}

Affected versions

Other
8
v1
v1-alpha1
v1-alpha2
v1-alpha3
v1-beta1
v1-beta2
v1-beta3
v13
v13-alpha
v13-alpha2
v13-rc1
v13-rc2
v15
v15-rc1
v16
v17
v17-rc1
v18
v18-rc1
v19
v2
v20
v20-rc1
v20-rc2
v20-rc3
v20-rc4
v21
v21-rc1
v21-rc2
v22
v22-rc1
v23
v24
v25
v25-rc1
v25-rc2
v25-rc3
v26
v27
v27-rc1
v28
v28-rc1
v29
v29-rc1
v29-rc2
v3
v30
v31
v31-rc1
v31-rc2
v32
v32-rc1
v33
v34
v34-rc1
v34-rc2
v35
v36
v37
v38
v38-rc1
v38-rc2
v38-rc3
v39
v4
v40
v40-rc1
v40-rc2
v40-rc3
v40-rc4
v40-rc5
v41
v42
v42-rc1
v43
v44
v46
v47
v48
v49
v5
v50
v54
v55
v56
v57
v58
v59
v6
v62
v63
v66
v67
v7
v8
v9
v1.*
v1.0.0.alpha.45
v1.0.0.alpha.46
v1.0.0.alpha.47
v1.0.0.alpha.48

Database specific

vanir_signatures_modified
"2026-07-22T04:02:49Z"
vanir_signatures
[
    {
        "target": {
            "function": "handshake_read_identity_cb",
            "file": "src/plugins/lan/valent-lan-channel-service.c"
        },
        "digest": {
            "length": 1153.0,
            "function_hash": "270469539013828858515992651566742368465"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2025-66270-0378a486",
        "source": "https://github.com/andyholmes/valent/commit/85f773124a67ed1add79e7465bb088ec667cccce"
    },
    {
        "target": {
            "file": "src/plugins/lan/valent-lan-channel-service.c"
        },
        "digest": {
            "line_hashes": [
                "295441420765439209793313560697992115129",
                "103547131321790095811207031624004175501",
                "4236644495770605623909284852238119502",
                "299189658745001810727134487762659583364",
                "109420901733764282823966585117706891840",
                "164753608904063504125764505165299078362",
                "286245813073815078493115232858446605233"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2025-66270-5e25422a",
        "source": "https://github.com/andyholmes/valent/commit/85f773124a67ed1add79e7465bb088ec667cccce"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66270.json"