Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 43: opentofu Critical DoS Memory Exhaustion Advisory 2025-6968ab200a

fedora
Calendar Grey December 29, 2025
Dist Fedora Esm H88
Critical Fedora security advisory for OpenTofu update addressing important issues and threats based on user reports.
Update to 1.11.2

Summary

OpenTofu lets you declaratively manage your cloud infrastructure.

Update Information:

Update to 1.11.2

Change Log

* Fri Dec 19 2025 Mikel Olasagasti Uranga - 1.11.2-1 - Update to 1.11.2 - Closes rhbz#2420199

References


[ 1 ] Bug #2408335 - CVE-2025-58189 opentofu: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408335 [ 2 ] Bug #2408738 - CVE-2025-61725 opentofu: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408738 [ 3 ] Bug #2409808 - CVE-2025-61723 opentofu: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409808 [ 4 ] Bug #2410758 - CVE-2025-58185 opentofu: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410758 [ 5 ] Bug #2411654 - CVE-2025-58188 opentofu: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411654

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6968ab200a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: opentofu
Product: Fedora 43
Version: 1.11.2
Release: 1.fc43
Summary: OpenTofu lets you declaratively manage your cloud infrastructure

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here