Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 9: Golang Critical DNS Constraint Advisory MGASA-2025-0326

mageia
Calendar Grey December 13, 2025
Dist Mageia Esm H88
Updated golang packages address security issues including DNS constraints and excessive resource use.
MGASA-2025-0326 - Updated golang packages fix security vulnerabilities

Summary

Description: Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509. (CVE-2025-61727) Excessive resource consumption when printing error string for host certificate validation in crypto/x509. (CVE-2025-61729)

References

- https://bugs.mageia.org/show_bug.cgi?id=34810

- https://www.openwall.com/lists/oss-security/2025/12/05/3

- https://www.cve.org/CVERecord?id=CVE-2025-61727

- https://www.cve.org/CVERecord?id=CVE-2025-61729

Resolution

SRPMS

- 9/core/golang-1.24.11-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 13 Dec 2025
URL: https://advisories.mageia.org/MGASA-2025-0326.html
Type: security
CVE: CVE-2025-61727, CVE-2025-61729

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here