xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
Cite this page
CVE-2016-6225. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2016-6225
Use CWE-326, Percona vendor hub and Xtrabackup product page to widen CVE-2016-6225 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-25834, CVE-2022-26944 and CVE-2020-10997 for nearby disclosures in the same product family.