CNNVD-202511-2443 Information
Nov 21, 2025
cve
CNNVD ID
CNNVD-202511-2443
Related CVE
- CNNVD Published: 2025-11-21
Description (Chinese)
Wazuh是Wazuh开源的一个应用软件。用于收集,汇总,索引和分析安全数据,帮助组织检测入侵,威胁和行为异常。 Wazuh 3.7.0版本至4.12.0之前版本存在代码问题漏洞,该漏洞源于fim_alert函数未检查空指针,可能导致analysisd崩溃。
Description (English)
Wazuh is an application from the Wazuh Open Source. For collection, aggregation, indexing and analysis of security data to help the organization detect invasions, threats and behavioural anomalies. Wazuh 3.7.0 to 4.12.0 had a code problem loophole, which arose from the failure of the fim alert function to check the empty pointer, which could lead to analysisd collapse.
Hazard Level
High
Vulnerability Type
代码问题
Affected Vendor
Wazuh
Published
2025-11-21
Last Modified
2026-02-24
References
https://github.com/wazuh/wazuh/security/advisories/GHSA-hc35-h924-8596 https://access.redhat.com/security/cve/cve-2025-64169
Patch
https://github.com/wazuh/wazuh/releases
Share on: