CVE-2025-61729

Updated: 2026-01-21 23:51:08.528798

Description:

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU golang 1.19.13 7.5 HIGH Released CLSA-2026:1770112258 2026-02-03 15:39:15
AlmaLinux 9.2 ESU butane 0.17.0 7.5 HIGH Released CLSA-2026:1772646645 2026-03-04 19:10:52
AlmaLinux 9.2 ESU buildah 1.29.1 7.5 HIGH Released CLSA-2026:1772455449 2026-03-02 13:41:22
AlmaLinux 9.2 ESU osbuild-composer 76 7.5 HIGH In Testing 2026-03-06 16:18:58
AlmaLinux 9.2 ESU git-lfs 3.2.0 7.5 HIGH Needs Triage 2026-03-06 02:08:41
AlmaLinux 9.2 ESU grafana 9.0.9 7.5 HIGH Released CLSA-2026:1772041183 2026-02-25 18:54:55
AlmaLinux 9.2 ESU podman 4.4.1 7.5 HIGH Released CLSA-2026:1772456640 2026-03-02 13:41:02
AlmaLinux 9.2 ESU grafana-pcp 5.1.1 7.5 HIGH Released CLSA-2026:1772040065 2026-02-25 18:54:15
AlmaLinux 9.2 ESU skopeo 1.11.2 7.5 HIGH Released CLSA-2026:1772812991 2026-03-06 16:20:35
AlmaLinux 9.2 ESU containernetworking-plugins 1.2.0 7.5 HIGH Released CLSA-2026:1772575666 2026-03-04 08:17:41
Total: 22