Back Linuxsecurity Fedora 42: kustomize Version 5.8.0 Update Advisory 2025
Customization of kubernetes YAML configurations. Update Information : Update to 5.8.0
Customization of kubernetes YAML configurations.
* Mon Dec 29 2025 Mikel Olasagasti Uranga - 5.8.0-1 - Update to 5.8.0 - Closes rhbz#2413654 * Fri Oct 10 2025 Maxwell G - 5.7.1-3 - Rebuild for golang 1.25.2 * Fri Aug 15 2025 Maxwell G - 5.7.1-2 - Rebuild for golang-1.25.0
* Mon Dec 29 2025 Mikel Olasagasti Uranga - 5.8.0-1 - Update to 5.8.0 - Closes rhbz#2413654 * Fri Oct 10 2025 Maxwell G - 5.7.1-3 - Rebuild for golang 1.25.2 * Fri Aug 15 2025 Maxwell G - 5.7.1-2 - Rebuild for golang-1.25.0
[ 1 ] Bug #2390876 - kustomize: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-42] [ 2 ] Bug #2398851 - CVE-2025-47910 kustomize: CrossOriginProtection bypass in net/http [fedora-42] [ 3 ] Bug #2399525 - CVE-2025-47906 kustomize: Unexpected paths returned from LookPath in os/exec [fedora-42] [ 4 ] Bug #2399724 - CVE-2025-11065 kustomize: Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure [fedora-42] [ 5 ] Bug #2408061 - CVE-2025-58189 kustomize: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] [ 6 ] Bug #2408675 - CVE-2025-61725 kustomize: Excessive CPU co... Read the Full Advisory
[ 1 ] Bug #2390876 - kustomize: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-42] [ 2 ] Bug #2398851 - CVE-2025-47910 kustomize: CrossOriginProtection bypass in net/http [fedora-42] [ 3 ] Bug #2399525 - CVE-2025-47906 kustomize: Unexpected paths returned from LookPath in os/exec [fedora-42] [ 4 ] Bug #2399724 - CVE-2025-11065 kustomize: Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure [fedora-42] [ 5 ] Bug #2408061 - CVE-2025-58189 kustomize: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] [ 6 ] Bug #2408675 - CVE-2025-61725 kustomize: Excessive CPU co...
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a887e86abc' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
