Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

openSUSE: go-sendxmpp Important Memory Issues Fix CVE-2025-47911

opensuse
Calendar Grey December 24, 2025
Dist Opensuse Esm H88
Update for go-sendxmpp resolves two important issues improving security and performance in openSUSE Backports.
An update that fixes two vulnerabilities is now available.

Description

This update for go-sendxmpp fixes the following issues:

Update to 0.15.1:

- Added

* Add XEP-0359 Origin-ID to messages (requires go-xmpp >= v0.2.18).

- Changed

* HTTP upload: Ignore timeouts on disco IQs as some components do not

reply.

Upgrades the embedded golang.org/x/net to 0.46.0

* Fixes: boo#1251461, CVE-2025-47911: various algorithms with quadratic

complexity when parsing HTML documents

* Fixes: boo#1251677, CVE-2025-58190: excessive memory consumption by

'html.ParseFragment' when processing specially crafted input

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2025-483=1

Package List

- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

go-sendxmpp-0.15.1-bp157.2.6.1

References

https://www.suse.com/security/cve/CVE-2025-47911.html

https://www.suse.com/security/cve/CVE-2025-58190.html

https://bugzilla.suse.com/1251461

https://bugzilla.suse.com/1251677

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2025:0483-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here