Bug 2407533
| Summary: | CVE-2025-58189 golang-github-facebook-time: go crypto/tls ALPN negotiation error contains attacker controlled information [epel-9] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora EPEL | Reporter: | Jon Moroney <jmoroney> |
| Component: | golang-github-facebook-time | Assignee: | Vadim Fedorenko <vadfed> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | epel9 | CC: | alexander.bulimov, davide, freya652rey, go-sig, leoleovich, michel, vadfed, yarikos |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["3315d28f-56bc-48ea-9391-3ff13568ea24"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2407260 | ||
|
Description
Jon Moroney
2025-10-30 18:56:06 UTC
Hi, another one on the tracker. Okay, 'best effort'—got it. So, the Product Security team is flagging it, but it's on me to dive in and confirm if this actually touches my package's code. Classic. I need to make sure I don't rush a fix for something that's not even a problem here. Checking the essential docs link now... better loop in the PSIRT guys https://www.md-ezpass.com if I find any conflicting info. Accountability check, initiated. This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component. |