Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Submariner
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Submariner
ID: RHSA-2025:9541
Distribution: Red Hat
Plattformen: Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9
Datum: Di, 24. Juni 2025, 22:07
Referenzen: https://access.redhat.com/security/cve/CVE-2025-30204
https://bugzilla.redhat.com/show_bug.cgi?id=2348366
https://access.redhat.com/security/cve/CVE-2025-22868
https://access.redhat.com/errata/RHSA-2025:9541
https://bugzilla.redhat.com/show_bug.cgi?id=2354195
Applikationen: Submariner

Originalnachricht

Submariner 0.17.6 packages fix bugs and adds enhancements that are now
available for Red Hat Advanced Cluster Management for Kubernetes version 2.10.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE links in the References section.

Submariner 0.17.6 enables direct networking between pods and services on
different Kubernetes clusters that are on-premises or in the cloud.

This advisory contains bug fixes and enhancements to the Submariner container
images.

Security fixes:

* golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing
in golang.org/x/oauth2/jws (CVE-2025-22868)
* golang-jwt/jwt: jwt-go allows excessive memory allocation during header
parsing (CVE-2025-30204)

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2025-22868: Improper Validation of Syntactic Correctness of Input
(CWE-1286)
CVE-2025-30204: Asymmetric Resource Consumption (Amplification) (CWE-405)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung