CVE-2016-6225: Fedoraproject Fedora

Medium severity, CVSS 5.9. EPSS: 1.1% chance of exploitation in the next 30 days.

xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.

Affected products

  • Fedoraproject Fedora: version 24 only; version 25 only
  • Opensuse Leap: version 42.1 only; version 42.2 only
  • Percona Xtrabackup: up to and including 2.3.5; version 2.4.0 only; version 2.4.1 only; version 2.4.2 only; version 2.4.3 only; version 2.4.4 only

Published 2017-03-23. Last modified 2026-06-17.