Back Linuxsecurity Fedora 42 SingularityCE Critical Update for Go CVEs 2025
SingularityCE is the Community Edition of Singularity, an open source container platform designed to be simple, fast, and secure. Update Information : Upgrade to 4.3.4 upstream version. Build with Go 1.24.9 fixes multiple Go CVEs BZ#2408093 BZ#2408688 BZ#2409563 BZ#2410514 BZ#2411412
SingularityCE is the Community Edition of Singularity, an open source
container platform designed to be simple, fast, and secure.
Upgrade to 4.3.4 upstream version. Build with Go 1.24.9 fixes multiple Go CVEs BZ#2408093 BZ#2408688 BZ#2409563 BZ#2410514 BZ#2411412
* Thu Oct 30 2025 David Trudgian - 4.3.4-1 - Upgrade to 4.3.4 upstream version.
* Thu Oct 30 2025 David Trudgian - 4.3.4-1 - Upgrade to 4.3.4 upstream version.
[ 1 ] Bug #2408093 - CVE-2025-58189 singularity-ce: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] [ 2 ] Bug #2408688 - CVE-2025-61725 singularity-ce: Excessive CPU consumption in ParseAddress in net/mail [fedora-42] [ 3 ] Bug #2409563 - CVE-2025-61723 singularity-ce: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] [ 4 ] Bug #2410514 - CVE-2025-58185 singularity-ce: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] [ 5 ] Bug #2411412 - CVE-2025-58188 singularity-ce: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42]
[ 1 ] Bug #2408093 - CVE-2025-58189 singularity-ce: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] [ 2 ] Bug #2408688 - CVE-2025-61725 singularity-ce: Excessive CPU consumption in ParseAddress in net/mail [fedora-42] [ 3 ] Bug #2409563 - CVE-2025-61723 singularity-ce: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] [ 4 ] Bug #2410514 - CVE-2025-58185 singularity-ce: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] [ 5 ] Bug #2411412 - CVE-2025-58188 singularity-ce: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-75b28e93c9' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
