Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 41: golang-github-openprinting-ipp-usb Critical Memory Leak Alert

fedora
Calendar Grey November 8, 2025
Dist Fedora Esm H88
This advisory reports a critical memory exhaustion flaw across multiple Go packages in Fedora 41. Immediate updates recommended.
Rebuild with the latest golang in repos

Summary

HTTP reverse proxy, backed by IPP-over-USB connection to device. It enables

driverless support for USB devices capable of using IPP-over-USB protocol.

Update Information:

Rebuild with the latest golang in repos

Change Log

* Fri Oct 31 2025 Zdenek Dohnal - 0.9.30-7 - Rebuild with the latest golang in repos * Fri Oct 10 2025 Maxwell G - 0.9.30-6 - Rebuild for golang 1.25.2 * Fri Aug 15 2025 Maxwell G - 0.9.30-5 - Rebuild for golang-1.25.0 * Thu Jul 24 2025 Fedora Release Engineering - 0.9.30-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild

References


[ 1 ] Bug #2407251 - CVE-2025-58185 encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 https://bugzilla.redhat.com/show_bug.cgi?id=2407251 [ 2 ] Bug #2407252 - CVE-2025-61723 encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem https://bugzilla.redhat.com/show_bug.cgi?id=2407252 [ 3 ] Bug #2407260 - CVE-2025-58189 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information https://bugzilla.redhat.com/show_bug.cgi?id=2407260

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9d12a32bce' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: golang-github-openprinting-ipp-usb
Product: Fedora 41
Version: 0.9.30
Release: 7.fc41
Summary: HTTP reverse proxy, backed by IPP-over-USB connection to device

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here