Description:
Insufficient validation of bracketed IPv6 hostnames in net/url.
(CVE-2025-47912)
Unbounded allocation when parsing GNU sparse map in archive/tar.
(CVE-2025-58183)
Parsing DER payload can cause memory exhaustion in encoding/asn1.
(CVE-2025-58185)
Lack of limit when parsing cookies can cause memory exhaustion in
net/http. (CVE-2025-58186)
Quadratic complexity when checking name constraints in crypto/x509.
(CVE-2025-58187)
Panic when validating certificates with DSA public keys in crypto/x509.
(CVE-2025-58188)
ALPN negotiation error contains attacker controlled information in
crypto/tls. (CVE-2025-58189)
Quadratic complexity when parsing some invalid inputs in encoding/pem.
(CVE-2025-61723)
Excessive CPU consumption in Reader.ReadResponse in net/textproto.
(CVE-2025-61724)
Excessive CPU consumption in ParseAddress in net/mail. (CVE-2025-61725)
These packages fix the issues for the compiler only; applications using the
functions still need to be rebuilt.
- https://bugs.mageia.org/show_bug.cgi?id=34651
- https://www.openwall.com/lists/oss-security/2025/10/08/1
- https://www.cve.org/CVERecord?id=CVE-2025-47912
- https://www.cve.org/CVERecord?id=CVE-2025-58183
- https://www.cve.org/CVERecord?id=CVE-2025-58185
- https://www.cve.org/CVERecord?id=CVE-2025-58186
- https://www.cve.org/CVERecord?id=CVE-2025-58187
- https://www.cve.org/CVERecord?id=CVE-2025-58188
- https://www.cve.org/CVERecord?id=CVE-2025-58189
- https://www.cve.org/CVERecord?id=CVE-2025-61723
- https://www.cve.org/CVERecord?id=CVE-2025-61724
- https://www.cve.org/CVERecord?id=CVE-2025-61725
- 9/core/golang-1.24.9-1.mga9
Get the latest Linux and open source security news straight to your inbox.