Bug 2410469
| Summary: | CVE-2025-58185 inspektor-gadget: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Jon Moroney <jmoroney> |
| Component: | inspektor-gadget | Assignee: | Kyle Gospodnetich <me> |
| Status: | CLOSED CANTFIX | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 42 | CC: | flaniel+fedora, go-sig, me |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["2fa18d6d-4a63-4751-8449-0bd327aaa2c7"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2025-11-05 14:47:52 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2407251 | ||
|
Description
Jon Moroney
2025-10-31 22:41:47 UTC
This is caused by golang version used to build ig, not by ig itself. Building with fixed golang will fix the issue. ig was built today to bump to v0.46.0. *** Bug 2410731 has been marked as a duplicate of this bug. *** |