Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-64429— DuckDB Encryption Crypto implementation is vulnerable

Quick assessment

Affected
duckdb duckdb
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

DuckDB是DuckDB开源的一个进程内 SQL OLAP 数据库管理系统。 DuckDB 1.4.0版本至1.4.2之前版本存在加密问题漏洞,该漏洞源于加密实现问题,可能导致密钥泄露或绕过完整性检查。

AI Predicted 8.1 Difficulty: Hard EPSS 0.11% · P1
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-64429

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DuckDB Encryption Crypto implementation is vulnerable
Source: CVE Program / CVE List V5
Vulnerability Description
DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this implementation. The DuckDB can fall back to an insecure random number generator (pcg32) to generate cryptographic keys or IVs. When clearing keys from memory, the compiler may remove the memset() and leave sensitive data on the heap. By modifying the database header, an attacker could downgrade the encryption mode from GCM to CTR to bypass integrity checks. There may be a failure to check return value on call to OpenSSL `rand_bytes()`. An attacker could use public IVs to compromise the internal state of RNG and determine the randomly generated key used to encrypt temporary files, get access to cryptographic keys if they have access to process memory (e.g. through memory leak),circumvent GCM integrity checks, and/or influence the OpenSSL random number generator and DuckDB would not be able to detect a failure of the generator. Version 1.4.2 has disabled the insecure random number generator by no longer using the fallback to write to or create databases. Instead, DuckDB will now attempt to install and load the OpenSSL implementation in the `httpfs` extension. DuckDB now uses secure MbedTLS primitive to clear memory as recommended and requires explicit specification of ciphers without integrity checks like CTR on `ATTACH`. Additionally, DuckDB now checks the return code.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用已被攻破或存在风险的密码学算法
Source: CVE Program / CVE List V5
Vulnerability Title
DuckDB 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DuckDB是DuckDB开源的一个进程内 SQL OLAP 数据库管理系统。 DuckDB 1.4.0版本至1.4.2之前版本存在加密问题漏洞,该漏洞源于加密实现问题,可能导致密钥泄露或绕过完整性检查。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
duckdb duckdb >= 1.4.0, < 1.4.2 -

II. Public POCs for CVE-2025-64429

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-64429

请登录查看更多情报信息。

Vendor Advisories for CVE-2025-64429 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-64429

No comments yet


Leave a comment