{"id":"CVE-2025-13470","title":"In RNP version 0.18.0 a refactoring regression causes the symmetric \nsession key used for Public-Key Encrypted Session Key (PKESK) packets to\n be left uninitialized except for zeroing, resulting in it always being \nan all-zero byte array…","summary":"In RNP version 0.18.0 a refactoring regression causes the symmetric \nsession key used for Public-Key Encrypted Session Key (PKESK) packets to\n be left uninitialized except for zeroing, resulting in it always being \nan all-zero byte array…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-330"],"published":"2025-11-21","updated":"2026-10-08","sourceUpdated":"2026-10-08T10:10:00.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13470","references":[{"url":"https://access.redhat.com/security/cve/cve-2025-13402","label":"6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3"},{"url":"https://aur.archlinux.org/packages/rnp","label":"6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2415863","label":"6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3"},{"url":"https://github.com/rnpgp/rnp/commit/7bd9a8dc356aae756b40755be76d36205b6b161a","label":"6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3"},{"url":"https://github.com/rnpgp/rnp/releases/tag/v0.18.1","label":"6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3"},{"url":"https://launchpad.net/ubuntu/+source/rnp","label":"6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3"},{"url":"https://open.ribose.com/advisories/ra-2025-11-20/","label":"6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3"},{"url":"https://packages.gentoo.org/packages/dev-util/librnp","label":"6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3"}],"tags":["nvd"],"epss":0.00301,"epssPercentile":0.20886,"ingestedAt":"2026-10-08T10:28:20.269Z","slug":"CVE-2025-13470","body":"## Overview\n\nIn RNP version 0.18.0 a refactoring regression causes the symmetric \nsession key used for Public-Key Encrypted Session Key (PKESK) packets to\n be left uninitialized except for zeroing, resulting in it always being \nan all-zero byte array.\n\nAny data encrypted using public-key encryption \nin this release can be decrypted trivially by supplying an all-zero \nsession key, fully compromising confidentiality.\n\nThe vulnerability affects only public key encryption (PKESK packets).  Passphrase-based encryption (SKESK packets) is not affected.\n\nRoot cause: Vulnerable session key buffer used in PKESK packet generation.\n\n\n\nThe defect was introduced in commit `7bd9a8dc356aae756b40755be76d36205b6b161a` where initialization \nlogic inside `encrypted_build_skesk()` only randomized the key for the \nSKESK path and omitted it for the PKESK path.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}