Skip to content
Fedora 42: kustomize Version 5.8.0 Update Advisory 2025

Fedora 42: kustomize Version 5.8.0 Update Advisory 2025

Linuxsecurity LinuxSecurity Advisories December 31, 2025

Customization of kubernetes YAML configurations. Update Information : Update to 5.8.0

Customization of kubernetes YAML configurations.

* Mon Dec 29 2025 Mikel Olasagasti Uranga - 5.8.0-1 - Update to 5.8.0 - Closes rhbz#2413654 * Fri Oct 10 2025 Maxwell G - 5.7.1-3 - Rebuild for golang 1.25.2 * Fri Aug 15 2025 Maxwell G - 5.7.1-2 - Rebuild for golang-1.25.0

* Mon Dec 29 2025 Mikel Olasagasti Uranga - 5.8.0-1 - Update to 5.8.0 - Closes rhbz#2413654 * Fri Oct 10 2025 Maxwell G - 5.7.1-3 - Rebuild for golang 1.25.2 * Fri Aug 15 2025 Maxwell G - 5.7.1-2 - Rebuild for golang-1.25.0

[ 1 ] Bug #2390876 - kustomize: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-42] [ 2 ] Bug #2398851 - CVE-2025-47910 kustomize: CrossOriginProtection bypass in net/http [fedora-42] [ 3 ] Bug #2399525 - CVE-2025-47906 kustomize: Unexpected paths returned from LookPath in os/exec [fedora-42] [ 4 ] Bug #2399724 - CVE-2025-11065 kustomize: Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure [fedora-42] [ 5 ] Bug #2408061 - CVE-2025-58189 kustomize: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] [ 6 ] Bug #2408675 - CVE-2025-61725 kustomize: Excessive CPU co... Read the Full Advisory

[ 1 ] Bug #2390876 - kustomize: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-42] [ 2 ] Bug #2398851 - CVE-2025-47910 kustomize: CrossOriginProtection bypass in net/http [fedora-42] [ 3 ] Bug #2399525 - CVE-2025-47906 kustomize: Unexpected paths returned from LookPath in os/exec [fedora-42] [ 4 ] Bug #2399724 - CVE-2025-11065 kustomize: Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure [fedora-42] [ 5 ] Bug #2408061 - CVE-2025-58189 kustomize: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] [ 6 ] Bug #2408675 - CVE-2025-61725 kustomize: Excessive CPU co...

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a887e86abc' at the command line. For more information, refer to the dnf documentation available at