Back Linuxsecurity Fedora 43: gh Update Advisory Critical CVE-2025-58189 and CVE-2025
A command-line interface to GitHub for use in your terminal or your scripts. gh is a tool designed to enhance your workflow when working with GitHub. It provides a seamless way to interact with GitHub repositories and perform various actions right from the command line, eliminating the need to switch between your terminal and the GitHub website. Update Information : Update to 2.83.0
A command-line interface to GitHub for use in your terminal or your scripts.
gh is a tool designed to enhance your workflow when working with GitHub. It
provides a seamless way to interact with GitHub repositories and perform various
actions right from the command line, eliminating the need to switch between your
terminal and the GitHub website.
* Tue Nov 4 2025 Packit - 2.83.0-1 - Update to 2.83.0 upstream release - Resolves: rhbz#2397664 * Fri Oct 10 2025 Alejandro Sez - 2.79.0-2 - rebuild
* Tue Nov 4 2025 Packit - 2.83.0-1 - Update to 2.83.0 upstream release - Resolves: rhbz#2397664 * Fri Oct 10 2025 Alejandro Sez - 2.79.0-2 - rebuild
[ 1 ] Bug #2408169 - CVE-2025-58189 gh: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] [ 2 ] Bug #2408706 - CVE-2025-61725 gh: Excessive CPU consumption in ParseAddress in net/mail [fedora-43]
[ 1 ] Bug #2408169 - CVE-2025-58189 gh: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] [ 2 ] Bug #2408706 - CVE-2025-61725 gh: Excessive CPU consumption in ParseAddress in net/mail [fedora-43]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6981d97f47' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
