Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 9: golang Critical Memory Issues Fix MGASA-2025-0256

mageia
Calendar Grey November 4, 2025
Dist Mageia Esm H88
Updated golang packages in Mageia address critical security flaws, including potential memory exhaustion attacks. Stay secure.
MGASA-2025-0256 - Updated golang packages fix security vulnerabilities

Summary

Description: Insufficient validation of bracketed IPv6 hostnames in net/url. (CVE-2025-47912) Unbounded allocation when parsing GNU sparse map in archive/tar. (CVE-2025-58183) Parsing DER payload can cause memory exhaustion in encoding/asn1. (CVE-2025-58185) Lack of limit when parsing cookies can cause memory exhaustion in net/http. (CVE-2025-58186) Quadratic complexity when checking name constraints in crypto/x509. (CVE-2025-58187) Panic when validating certificates with DSA public keys in crypto/x509. (CVE-2025-58188) ALPN negotiation error contains attacker controlled information in crypto/tls. (CVE-2025-58189) Quadratic complexity when parsing some invalid inputs in encoding/pem. (CVE-2025-61723) Excessive CPU consumption in Reader.ReadResponse in net/textproto. (CVE-2025-61724) Excessive CPU consumption in ParseAddress in net/mail. (CVE-2025-61725) These packages fix the issues for the compiler only; applications using the functions still need to be rebuilt.

References

- https://bugs.mageia.org/show_bug.cgi?id=34651

- https://www.openwall.com/lists/oss-security/2025/10/08/1

- https://www.cve.org/CVERecord?id=CVE-2025-47912

- https://www.cve.org/CVERecord?id=CVE-2025-58183

- https://www.cve.org/CVERecord?id=CVE-2025-58185

- https://www.cve.org/CVERecord?id=CVE-2025-58186

- https://www.cve.org/CVERecord?id=CVE-2025-58187

- https://www.cve.org/CVERecord?id=CVE-2025-58188

- https://www.cve.org/CVERecord?id=CVE-2025-58189

- https://www.cve.org/CVERecord?id=CVE-2025-61723

- https://www.cve.org/CVERecord?id=CVE-2025-61724

- https://www.cve.org/CVERecord?id=CVE-2025-61725

Resolution

SRPMS

- 9/core/golang-1.24.9-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 04 Nov 2025
URL: https://advisories.mageia.org/MGASA-2025-0256.html
Type: security
CVE: CVE-2025-47912, CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-2025-58187, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723, CVE-2025-61724, CVE-2025-61725

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here