Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 43: openbao Critical Root Escalation Fix 2025-c7f4367479

fedora
Calendar Grey December 3, 2025
Dist Fedora Esm H88
Update to openbao 2.4.4 fixes several critical access issues in Fedora 43 including CVE-2025-64761.
update to upstream 2.4.4, fixing CVE-2025-64761

Summary

Openbao secures, stores, and tightly controls access to tokens, passwords,

certificates, API keys, and other secrets in modern computing. Openbao handles

leasing, key revocation, key rolling, and auditing. Through a unified API, users

can access an encrypted Key/Value store and network encryption-as-a-service, or

generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH

credentials, and more.

Update Information:

update to upstream 2.4.4, fixing CVE-2025-64761. Adds hsm tag. The fedora-43 build was done with golang-1.25.4 which fixed CVE-2025-58189, CVE-2025-58188, CVE-2025-61725, CVE-2025-61723, CVE-2025-58185, and CVE-2025-58183.

Change Log

* Mon Nov 24 2025 Dave Dykstra <2129743+DrDaveD@users.noreply.github.com> - 2.4.4-1 - update to 2.4.4 * Tue Nov 18 2025 Dave Dykstra <2129743+DrDaveD@users.noreply.github.com> - 2.4.3-2 - add hsm build tag

References


[ 1 ] Bug #2408334 - CVE-2025-58189 openbao: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408334 [ 2 ] Bug #2408737 - CVE-2025-61725 openbao: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408737 [ 3 ] Bug #2409807 - CVE-2025-61723 openbao: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409807 [ 4 ] Bug #2410757 - CVE-2025-58185 openbao: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410757 [ 5 ] Bug #2411653 - CVE-2025-58188 openbao: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411653 [ 6 ] Bug #2417146 - CVE-2025-64761 openbao: OpenBao...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c7f4367479' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: openbao
Product: Fedora 43
Version: 2.4.4
Release: 1.fc43
Summary: A tool for securely accessing secrets

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here