Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Fedora 42: Apptainer Critical Memory Leak CVE-2025-58058 Advisory

fedora
Calendar Grey October 8, 2025
Dist Fedora Esm H88
Upgrade to Apptainer 1.4.3 addresses CVE-2025-58058 memory leak in Fedora 42 environment. Immediate action is advised.
Update to upstream 1.4.3, fix CVE-2025-58058

Summary

Apptainer provides functionality to make portable

containers that can be used across host environments.

Update Information:

Update to upstream 1.4.3, fix CVE-2025-58058

Change Log

* Mon Sep 29 2025 Dave Dykstra - 1.4.3 - Update to upstream 1.4.3

References


[ 1 ] Bug #2391600 - CVE-2025-58058 apptainer: github.com/ulikunitz/xz leaks memory [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2391600 [ 2 ] Bug #2391608 - CVE-2025-58058 apptainer: github.com/ulikunitz/xz leaks memory [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2391608 [ 3 ] Bug #2391610 - CVE-2025-58058 apptainer: github.com/ulikunitz/xz leaks memory [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2391610 [ 4 ] Bug #2391617 - CVE-2025-58058 apptainer: github.com/ulikunitz/xz leaks memory [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2391617 [ 5 ] Bug #2391646 - CVE-2025-58058 apptainer: github.com/ulikunitz/xz leaks memory [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2391646 [ 6 ] Bug #2398283 - CVE-2025-47910 apptainer: CrossOriginProtection bypass in net/http [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2398283 [ 7 ] Bug #2398318 - CVE-2025-47910 appta...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-402b80a0de' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: apptainer
Product: Fedora 42
Version: 1.4.3
Release: 1.fc42
Summary: Application and environment virtualization formerly known as Singularity

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here