Back Linuxsecurity Fedora 43: Critical Vulnerabilities in golang-github-openprinting-ipp
HTTP reverse proxy, backed by IPP-over-USB connection to device. It enables driverless support for USB devices capable of using IPP-over-USB protocol. Update Information : Rebuild with the latest golang in repos
HTTP reverse proxy, backed by IPP-over-USB connection to device. It enables
driverless support for USB devices capable of using IPP-over-USB protocol.
Rebuild with the latest golang in repos
* Fri Oct 31 2025 Zdenek Dohnal - 0.9.30-7 - Rebuild with the latest golang in repos * Fri Oct 10 2025 Maxwell G - 0.9.30-6 - Rebuild for golang 1.25.2
* Fri Oct 31 2025 Zdenek Dohnal - 0.9.30-7 - Rebuild with the latest golang in repos * Fri Oct 10 2025 Maxwell G - 0.9.30-6 - Rebuild for golang 1.25.2
[ 1 ] Bug #2407251 - CVE-2025-58185 encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 [ 2 ] Bug #2407252 - CVE-2025-61723 encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem [ 3 ] Bug #2407260 - CVE-2025-58189 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information
[ 1 ] Bug #2407251 - CVE-2025-58185 encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 [ 2 ] Bug #2407252 - CVE-2025-61723 encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem [ 3 ] Bug #2407260 - CVE-2025-58189 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-46b6a955b3' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
