Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 43: kustomize Critical Issues CVE-2025-58189 RHSA-2025-ecfd96d6a3

fedora
Calendar Grey December 31, 2025
Dist Fedora Esm H88
Kustomize update for Fedora 43 addresses critical vulnerabilities including memory exhaustion and excessive CPU usage.
Update to 5.8.0

Summary

Customization of kubernetes YAML configurations.

Update Information:

Update to 5.8.0

Change Log

* Mon Dec 29 2025 Mikel Olasagasti Uranga - 5.8.0-1 - Update to 5.8.0 - Closes rhbz#2413654 * Fri Oct 10 2025 Maxwell G - 5.7.1-3 - Rebuild for golang 1.25.2

References


[ 1 ] Bug #2408318 - CVE-2025-58189 kustomize: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408318 [ 2 ] Bug #2408733 - CVE-2025-61725 kustomize: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408733 [ 3 ] Bug #2409791 - CVE-2025-61723 kustomize: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409791 [ 4 ] Bug #2410741 - CVE-2025-58185 kustomize: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410741 [ 5 ] Bug #2411637 - CVE-2025-58188 kustomize: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411637

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ecfd96d6a3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: kustomize
Product: Fedora 43
Version: 5.8.0
Release: 1.fc43
Summary: Customization of kubernetes YAML configurations

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here