Bug 2391649 - CVE-2025-58058 checkpointctl: github.com/ulikunitz/xz leaks memory [fedora-42]
Summary: CVE-2025-58058 checkpointctl: github.com/ulikunitz/xz leaks memory [fedora-42]
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: checkpointctl
Version: 42
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Radostin Stoyanov
QA Contact:
URL:
Whiteboard: {"flaws": ["a965347e-482c-4573-80d1-a...
Depends On:
Blocks: CVE-2025-58058
TreeView+ depends on / blocked
 
Reported: 2025-08-28 23:41 UTC by Jon Moroney
Modified: 2025-09-23 01:47 UTC (History)
4 users (show)

Fixed In Version: checkpointctl-1.4.0-2.el9 checkpointctl-1.4.0-2.fc42 checkpointctl-1.4.0-2.fc43 checkpointctl-1.4.0-3.fc43 checkpointctl-1.4.0-3.el9 checkpointctl-1.4.0-3.fc42 checkpointctl-1.4.0-3.fc41
Clone Of:
Environment:
Last Closed: 2025-09-12 00:27:07 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jon Moroney 2025-08-28 23:41:22 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams

Comment 1 Fedora Update System 2025-09-01 12:19:29 UTC
FEDORA-2025-aa879cbca1 (checkpointctl-1.4.0-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-aa879cbca1

Comment 2 Fedora Update System 2025-09-01 12:20:36 UTC
FEDORA-2025-198295e38c (checkpointctl-1.4.0-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-198295e38c

Comment 3 Fedora Update System 2025-09-01 12:29:46 UTC
FEDORA-EPEL-2025-ac1be4bde2 (checkpointctl-1.4.0-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-ac1be4bde2

Comment 4 Fedora Update System 2025-09-02 00:19:44 UTC
FEDORA-EPEL-2025-ac1be4bde2 has been pushed to the Fedora EPEL 9 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-ac1be4bde2

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2025-09-02 00:50:38 UTC
FEDORA-2025-aa879cbca1 has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-aa879cbca1`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-aa879cbca1

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2025-09-02 01:13:50 UTC
FEDORA-2025-198295e38c has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-198295e38c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-198295e38c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2025-09-04 01:12:14 UTC
FEDORA-2025-9b094ba1d6 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-9b094ba1d6`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-9b094ba1d6

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 8 Fedora Update System 2025-09-04 01:19:06 UTC
FEDORA-EPEL-2025-938ea797ca has been pushed to the Fedora EPEL 9 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-938ea797ca

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 9 Fedora Update System 2025-09-04 01:48:12 UTC
FEDORA-2025-ba1dacf88c has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-ba1dacf88c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-ba1dacf88c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 10 Tuomo Soini 2025-09-04 14:34:09 UTC
There is a serious issue in latest pacakge (1.4.0-2) - it drops Epoch so it doesn't update previous versions. Please rebuild with Epoch: 1

Comment 11 Radostin Stoyanov 2025-09-08 07:28:17 UTC
Thank you for your comment. Indeed, the Epoch field was accidently removed when applying the changes from https://src.fedoraproject.org/rpms/checkpointctl/pull-request/1
I've updated the package with a fix.

Comment 12 Fedora Update System 2025-09-12 00:27:07 UTC
FEDORA-EPEL-2025-938ea797ca (checkpointctl-1.4.0-2.el9) has been pushed to the Fedora EPEL 9 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 13 Fedora Update System 2025-09-12 02:06:20 UTC
FEDORA-2025-ba1dacf88c (checkpointctl-1.4.0-2.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 14 Tuomo Soini 2025-09-12 07:02:37 UTC
epel9 package is still missing new build with epoch fix.

Comment 15 Tuomo Soini 2025-09-12 07:04:20 UTC
And I just checked fc42 package - it also didn't get release bump and rebuild. so while fixed in fedora git there is no fixed build.

Comment 16 Fedora Update System 2025-09-12 19:28:08 UTC
FEDORA-2025-9b094ba1d6 (checkpointctl-1.4.0-2.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 17 Fedora Update System 2025-09-14 13:03:14 UTC
FEDORA-EPEL-2025-653f3a3664 (checkpointctl-1.4.0-3.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-653f3a3664

Comment 18 Fedora Update System 2025-09-14 13:04:16 UTC
FEDORA-2025-11b6deb0b8 (checkpointctl-1.4.0-3.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-11b6deb0b8

Comment 19 Fedora Update System 2025-09-14 13:05:22 UTC
FEDORA-2025-eda09a0a51 (checkpointctl-1.4.0-3.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-eda09a0a51

Comment 20 Fedora Update System 2025-09-14 13:05:59 UTC
FEDORA-2025-15f6a132bf (checkpointctl-1.4.0-3.fc41) has been submitted as an update to Fedora 41.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-15f6a132bf

Comment 21 Fedora Update System 2025-09-15 01:33:28 UTC
FEDORA-2025-eda09a0a51 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-eda09a0a51`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-eda09a0a51

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 22 Fedora Update System 2025-09-15 01:40:06 UTC
FEDORA-EPEL-2025-653f3a3664 has been pushed to the Fedora EPEL 9 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-653f3a3664

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 23 Fedora Update System 2025-09-15 01:51:24 UTC
FEDORA-2025-11b6deb0b8 has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-11b6deb0b8`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-11b6deb0b8

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 24 Fedora Update System 2025-09-15 02:35:03 UTC
FEDORA-2025-15f6a132bf has been pushed to the Fedora 41 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-15f6a132bf`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-15f6a132bf

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 25 Fedora Update System 2025-09-23 00:15:23 UTC
FEDORA-2025-eda09a0a51 (checkpointctl-1.4.0-3.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 26 Fedora Update System 2025-09-23 00:38:06 UTC
FEDORA-EPEL-2025-653f3a3664 (checkpointctl-1.4.0-3.el9) has been pushed to the Fedora EPEL 9 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 27 Fedora Update System 2025-09-23 01:12:40 UTC
FEDORA-2025-11b6deb0b8 (checkpointctl-1.4.0-3.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 28 Fedora Update System 2025-09-23 01:47:32 UTC
FEDORA-2025-15f6a132bf (checkpointctl-1.4.0-3.fc41) has been pushed to the Fedora 41 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.