Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-22874

Опубликовано: 11 июн. 2025
Источник: debian

Описание

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.24fixed1.24.4-1package
golang-1.23not-affectedpackage
golang-1.19not-affectedpackage
golang-1.15not-affectedpackage

Примечания

  • https://github.com/golang/go/issues/73612

  • Fixed by: https://github.com/golang/go/commit/03811ab1b31525e8d779997db169c6fedab7c505 (go1.24.4)

  • Introduced with: https://github.com/golang/go/commit/e8d95619978c4602d4446f113b3b69b7a22308fa (go1.24rc1)

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

CVSS3: 7.5
redhat
5 месяцев назад

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

CVSS3: 7.5
nvd
5 месяцев назад

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

CVSS3: 7.5
msrc
4 месяца назад

Usage of ExtKeyUsageAny disables policy validation in crypto/x509

CVSS3: 7.5
github
5 месяцев назад

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.