Skip to content
Fedora 42 SingularityCE Critical Update for Go CVEs 2025

Fedora 42 SingularityCE Critical Update for Go CVEs 2025

Linuxsecurity LinuxSecurity Advisories November 8, 2025

SingularityCE is the Community Edition of Singularity, an open source container platform designed to be simple, fast, and secure. Update Information : Upgrade to 4.3.4 upstream version. Build with Go 1.24.9 fixes multiple Go CVEs BZ#2408093 BZ#2408688 BZ#2409563 BZ#2410514 BZ#2411412

SingularityCE is the Community Edition of Singularity, an open source

container platform designed to be simple, fast, and secure.

Upgrade to 4.3.4 upstream version. Build with Go 1.24.9 fixes multiple Go CVEs BZ#2408093 BZ#2408688 BZ#2409563 BZ#2410514 BZ#2411412

* Thu Oct 30 2025 David Trudgian - 4.3.4-1 - Upgrade to 4.3.4 upstream version.

* Thu Oct 30 2025 David Trudgian - 4.3.4-1 - Upgrade to 4.3.4 upstream version.

[ 1 ] Bug #2408093 - CVE-2025-58189 singularity-ce: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] [ 2 ] Bug #2408688 - CVE-2025-61725 singularity-ce: Excessive CPU consumption in ParseAddress in net/mail [fedora-42] [ 3 ] Bug #2409563 - CVE-2025-61723 singularity-ce: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] [ 4 ] Bug #2410514 - CVE-2025-58185 singularity-ce: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] [ 5 ] Bug #2411412 - CVE-2025-58188 singularity-ce: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42]

[ 1 ] Bug #2408093 - CVE-2025-58189 singularity-ce: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] [ 2 ] Bug #2408688 - CVE-2025-61725 singularity-ce: Excessive CPU consumption in ParseAddress in net/mail [fedora-42] [ 3 ] Bug #2409563 - CVE-2025-61723 singularity-ce: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] [ 4 ] Bug #2410514 - CVE-2025-58185 singularity-ce: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] [ 5 ] Bug #2411412 - CVE-2025-58188 singularity-ce: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-75b28e93c9' at the command line. For more information, refer to the dnf documentation available at