It was discovered that the crypto_core_ed25519_is_valid_point() function of the Sodium cryptography library mishandled checks for valid elliptic curve points.
https://security-tracker.debian.org/tracker/DSA-6094-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-6094-1
Continue reading...

