Signed to Unsigned Conversion Error Affecting trustee-guest-components package, versions *


Severity

Recommended
0.0
medium
0
10

Based on CentOS security rating.

Threat Intelligence

EPSS
0.17% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS10-TRUSTEEGUESTCOMPONENTS-14460562
  • published18 Dec 2025
  • disclosed14 Dec 2025

Introduced: 14 Dec 2025

CVE-2025-67897  (opens in a new tab)
CWE-195  (opens in a new tab)

How to fix?

There is no fixed version for Centos:10 trustee-guest-components.

NVD Description

Note: Versions mentioned in the description apply only to the upstream trustee-guest-components package and not the trustee-guest-components package as distributed by Centos. See How to fix? for Centos:10 relevant fixed versions and status.

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

CVSS Base Scores

version 3.1