CVE Explorer
CVE-2025-64429
DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this implementation. The DuckDB can fall back to an insecure random number generator (pcg32) to generate cryptographic keys or IVs. When clearing keys from memory, the compiler may remove the memset() and leave sensitive data on the heap. By modifying the database header, an attacker could downgrade the encryption mode from GC
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"duckdb","vendor":"duckdb","versions":[{"status":"affected","version":">= 1.4.0, < 1.4.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:760fbe630707394eeca0bb827f35cb9b5c1595d346324e61b5282cf436827295 · sha256:496dcaae172a7460… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:760fbe630707394eeca0bb827f35cb9b5c1595d346324e61b5282cf436827295 · sha256:496dcaae172a7460… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-327","description":"CWE-327: Use of a Broken or Risky Cryptographic Algorithm","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:760fbe630707394eeca0bb827f35cb9b5c1595d346324e61b5282cf436827295 · sha256:496dcaae172a7460… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://duckdb.org/2025/09/16/announcing-duckdb-140.html","tags":["x_refsource_MISC"],"url":"https://duckdb.org/2025/09/16/announcing-duckdb-140.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:760fbe630707394eeca0bb827f35cb9b5c1595d346324e61b5282cf436827295 · sha256:496dcaae172a7460… · /containers/cna/references/2
{"name":"https://github.com/duckdb/duckdb/blob/029a5b87ff5b1cd22f7f9717d48cd8830d00807c/src/common/random_engine.cpp#L20","tags":["x_refsource_MISC"],"url":"https://github.com/duckdb/duckdb/blob/029a5b87ff5b1cd22f7f9717d48cd8830d00807c/src/common/random_engine.cpp#L20"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:760fbe630707394eeca0bb827f35cb9b5c1595d346324e61b5282cf436827295 · sha256:496dcaae172a7460… · /containers/cna/references/3
{"name":"https://github.com/duckdb/duckdb/pull/17275","tags":["x_refsource_MISC"],"url":"https://github.com/duckdb/duckdb/pull/17275"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:760fbe630707394eeca0bb827f35cb9b5c1595d346324e61b5282cf436827295 · sha256:496dcaae172a7460… · /containers/cna/references/1
{"name":"https://github.com/duckdb/duckdb/security/advisories/GHSA-vmp8-hg63-v2hp","tags":["x_refsource_CONFIRM"],"url":"https://github.com/duckdb/duckdb/security/advisories/GHSA-vmp8-hg63-v2hp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:760fbe630707394eeca0bb827f35cb9b5c1595d346324e61b5282cf436827295 · sha256:496dcaae172a7460… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.