{"id":"MGASA-2025-0256","summary":"Updated golang packages fix security vulnerabilities","details":"Insufficient validation of bracketed IPv6 hostnames in net/url.\n(CVE-2025-47912)\nUnbounded allocation when parsing GNU sparse map in archive/tar.\n(CVE-2025-58183)\nParsing DER payload can cause memory exhaustion in encoding/asn1.\n(CVE-2025-58185)\nLack of limit when parsing cookies can cause memory exhaustion in\nnet/http. (CVE-2025-58186)\nQuadratic complexity when checking name constraints in crypto/x509.\n(CVE-2025-58187)\nPanic when validating certificates with DSA public keys in crypto/x509.\n(CVE-2025-58188)\nALPN negotiation error contains attacker controlled information in\ncrypto/tls. (CVE-2025-58189)\nQuadratic complexity when parsing some invalid inputs in encoding/pem.\n(CVE-2025-61723)\nExcessive CPU consumption in Reader.ReadResponse in net/textproto.\n(CVE-2025-61724)\nExcessive CPU consumption in ParseAddress in net/mail. (CVE-2025-61725)\nThese packages fix the issues for the compiler only; applications using the\nfunctions still need to be rebuilt.\n","modified":"2026-02-04T03:09:29.919292Z","published":"2025-11-04T16:13:29Z","related":["CVE-2025-47912","CVE-2025-58183","CVE-2025-58185","CVE-2025-58186","CVE-2025-58187","CVE-2025-58188","CVE-2025-58189","CVE-2025-61723","CVE-2025-61724","CVE-2025-61725"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2025-0256.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=34651"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2025/10/08/1"}],"affected":[{"package":{"name":"golang","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/golang?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.24.9-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0256.json"}}],"schema_version":"1.7.3","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}