← Vulnerability feed

Vulnerability record · CVE-2025-65409 · published 30 December 2025

CVE-2025-65409: Gnu recutils divide by zero vulnerability

Gnu · Recutils

A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Service (DoS) via inputting an empty value as a password.

7.5 CVSS 3.1 High EPSS 0.36% · top 73.3% CWE-369 · Divide by zero
7.5CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Service (DoS) via inputting an empty value as a password.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-65409 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-11639Gnu recutils out-of-bounds write vulnerabilityAn issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum at rec-types.c in librec.a.EPSS 1.9%8.8CVE-2019-11640Gnu recutils out-of-bounds write vulnerabilityAn issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_simple at rec-fex.c in librec.a.EPSS 1.9%6.5CVE-2019-11637Gnu recutils out-of-bounds read vulnerabilityAn issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leadin…EPSS 1.4%6.5CVE-2019-11638Gnu recutils out-of-bounds read vulnerabilityAn issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec…EPSS 1.4%6.5CVE-2019-6455Gnu recutils double free vulnerabilityAn issue was discovered in GNU Recutils 1.8. There is a double-free problem in the function rec_mset_elem_destroy() in the file rec-mset.c.EPSS 1.3%6.5CVE-2019-6456Gnu recutils null pointer dereference vulnerabilityAn issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_fex_size() in the file rec-fex.c of librec.a.EPSS 1.3%6.5CVE-2019-6457Gnu recutils memory leak vulnerabilityAn issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_aggregate_reg_new in rec-aggregate.c in librec.a.EPSS 1.3%6.5CVE-2019-6458Gnu recutils memory leak vulnerabilityAn issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_buf_new in rec-buf.c when called from rec_parse_rset in rec-parser.c in li…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2025-65409), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.