Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:3681-1

Опубликовано: 11 нояб. 2025
Источник: suse-cvrf

Описание

Security update for go1.25

This update for go1.25 fixes the following issues:

go1.25.3 (released 2025-10-13) includes fixes to the crypto/x509 package. (bsc#1244485 CVE-2025-58187)

  • go#75861 crypto/x509: TLS validation fails for FQDNs with trailing dot

  • go#75777 spec: Go1.25 spec should be dated closer to actual release date

  • Further fixups to the fix for net/url allowing IP literals with IPv4 mapped IPv6 addresses.

Список пакетов

Container bci/golang:1.25
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Enterprise Storage 7.1
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise Module for Development Tools 15 SP6
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise Server 15 SP3-LTSS
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise Server 15 SP4-LTSS
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise Server 15 SP5-LTSS
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1
openSUSE Leap 15.6
go1.25-1.25.3-150000.1.19.1
go1.25-doc-1.25.3-150000.1.19.1
go1.25-race-1.25.3-150000.1.19.1

Описание

Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.


Затронутые продукты
Container bci/golang:1.25:go1.25-1.25.3-150000.1.19.1
Container bci/golang:1.25:go1.25-doc-1.25.3-150000.1.19.1
Container bci/golang:1.25:go1.25-race-1.25.3-150000.1.19.1
SUSE Enterprise Storage 7.1:go1.25-1.25.3-150000.1.19.1

Ссылки
Уязвимость SUSE-SU-2025:3681-1