PT-2025-42741 · Unknown+4 · Golang-1.19+5
Jakub Ciolek
·
Published
2025-01-01
·
Updated
2026-05-21
·
CVE-2025-58188
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Go versions prior to 1.24.9-alt1
Gobuster version 3.8.2
complyctl (affected versions not specified)
containernetworking-plugins version 1.9.0
OpenTofu (affected versions not specified)
Description
The Go programming language contains a flaw in the
crypto/x509 component where validating certificate chains with DSA public keys can lead to a program panic due to an incorrect interface cast. This occurs because the code expects DSA public keys to implement the Equal method. Exploitation of this issue by a remote attacker can result in a denial-of-service condition. Additionally, OpenTofu is affected by a denial-of-service issue in the "tofu init" function when processing maliciously crafted module package responses. Fedora has released updates for containernetworking-plugins, Gobuster, and complyctl to address security vulnerabilities, including CVE-2025-58188.Recommendations
Update Go to version 1.24.9-alt1 or later.
Update Gobuster to version 3.8.2.
Apply the latest security updates for complyctl.
Update containernetworking-plugins to version 1.9.0.
Apply the latest security updates for OpenTofu.
Fix
DoS
Improper Resource Release
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Red Os
Suse
Golang-1.15
Golang-1.19