---
id: CVE-2025-13470
title: |-
  In RNP version 0.18.0 a refactoring regression causes the symmetric 
  session key used for Public-Key Encrypted Session Key (PKESK) packets to
   be left uninitialized except for zeroing, resulting in it always being 
  an all-zero byte array…
summary: |-
  In RNP version 0.18.0 a refactoring regression causes the symmetric 
  session key used for Public-Key Encrypted Session Key (PKESK) packets to
   be left uninitialized except for zeroing, resulting in it always being 
  an all-zero byte array…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-330
published: '2025-11-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13470'
references:
  - url: 'https://access.redhat.com/security/cve/cve-2025-13402'
    label: 6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3
  - url: 'https://aur.archlinux.org/packages/rnp'
    label: 6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2415863'
    label: 6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3
  - url: >-
      https://github.com/rnpgp/rnp/commit/7bd9a8dc356aae756b40755be76d36205b6b161a
    label: 6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3
  - url: 'https://github.com/rnpgp/rnp/releases/tag/v0.18.1'
    label: 6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3
  - url: 'https://launchpad.net/ubuntu/+source/rnp'
    label: 6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3
  - url: 'https://open.ribose.com/advisories/ra-2025-11-20/'
    label: 6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3
  - url: 'https://packages.gentoo.org/packages/dev-util/librnp'
    label: 6504adb2-f5e9-4c9b-9eda-5e19c93bd9b3
tags:
  - nvd
epss: 0.00301
epssPercentile: 0.20886
ingestedAt: '2026-10-08T10:28:20.269Z'
---

## Overview

In RNP version 0.18.0 a refactoring regression causes the symmetric 
session key used for Public-Key Encrypted Session Key (PKESK) packets to
 be left uninitialized except for zeroing, resulting in it always being 
an all-zero byte array.

Any data encrypted using public-key encryption 
in this release can be decrypted trivially by supplying an all-zero 
session key, fully compromising confidentiality.

The vulnerability affects only public key encryption (PKESK packets).  Passphrase-based encryption (SKESK packets) is not affected.

Root cause: Vulnerable session key buffer used in PKESK packet generation.



The defect was introduced in commit `7bd9a8dc356aae756b40755be76d36205b6b161a` where initialization 
logic inside `encrypted_build_skesk()` only randomized the key for the 
SKESK path and omitted it for the PKESK path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
