Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 43: complyctl Vulnerability CVE-2025-58188 with Moderate Panic Risk

fedora
Calendar Grey January 14, 2026
Dist Fedora Esm H88
Update for complyctl on Fedora 43 addresses security concerns related to certificate validation.
Update to Upstream version 0.1.2 - https://github.com/complytime/complyctl/releases/tag/v0.1.2

Summary

complyctl leverages OSCAL to perform compliance assessment activities, using

plugins for each stage of the life-cycle.

Update Information:

Update to Upstream version 0.1.2 - https://github.com/complytime/complyctl/releases/tag/v0.1.2

Change Log

* Fri Dec 19 2025 Packit - 0.1.2-1 - Update to version 0.1.2

References


[ 1 ] Bug #2411187 - CVE-2025-58188 complyctl: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411187 [ 2 ] Bug #2411452 - CVE-2025-58188 complyctl: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411452 [ 3 ] Bug #2420579 - CVE-2025-47913 complyctl: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2420579 [ 4 ] Bug #2420609 - CVE-2025-47913 complyctl: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2420609

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-aa8453cfd0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: complyctl
Product: Fedora 43
Version: 0.1.2
Release: 1.fc43
Summary: Tool to perform compliance assessment activities, scaled by plugins

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here