PT-2025-19728 · Buoyant · Linkerd+1

John Howard

·

Published

2025-05-05

·

Updated

2025-05-22

·

CVE-2025-43915

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Linkerd versions 2.16.* through 2.16.4 Linkerd versions 2.17.* through 2.17.1 Linkerd versions 2.18.* (no specific end version mentioned, but before 2.18.0) Buoyant Edge versions before edge-25.2.1
Description Resource exhaustion can occur for Linkerd proxy metrics in the specified versions.
Recommendations For Linkerd versions 2.16.* through 2.16.4, update to version 2.16.5 or later. For Linkerd versions 2.17.* through 2.17.1, update to version 2.17.2 or later. For Linkerd versions 2.18.* before 2.18.0, update to version 2.18.0 or later. For Buoyant Edge versions before edge-25.2.1, update to version edge-25.2.1 or later.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2025-43915
GHSA-42MR-JPWH-M9RV
GO-2025-3664
OPENSUSE-SU-2025:15144-1

Affected Products

Buoyant Edge
Linkerd