Skip to content
Fedora 43: kustomize Critical Issues CVE-2025-58189 RHSA-2025

Fedora 43: kustomize Critical Issues CVE-2025-58189 RHSA-2025

Linuxsecurity LinuxSecurity Advisories December 31, 2025

Customization of kubernetes YAML configurations. Update Information : Update to 5.8.0

Customization of kubernetes YAML configurations.

* Mon Dec 29 2025 Mikel Olasagasti Uranga - 5.8.0-1 - Update to 5.8.0 - Closes rhbz#2413654 * Fri Oct 10 2025 Maxwell G - 5.7.1-3 - Rebuild for golang 1.25.2

* Mon Dec 29 2025 Mikel Olasagasti Uranga - 5.8.0-1 - Update to 5.8.0 - Closes rhbz#2413654 * Fri Oct 10 2025 Maxwell G - 5.7.1-3 - Rebuild for golang 1.25.2

[ 1 ] Bug #2408318 - CVE-2025-58189 kustomize: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] [ 2 ] Bug #2408733 - CVE-2025-61725 kustomize: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] [ 3 ] Bug #2409791 - CVE-2025-61723 kustomize: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] [ 4 ] Bug #2410741 - CVE-2025-58185 kustomize: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] [ 5 ] Bug #2411637 - CVE-2025-58188 kustomize: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43]

[ 1 ] Bug #2408318 - CVE-2025-58189 kustomize: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] [ 2 ] Bug #2408733 - CVE-2025-61725 kustomize: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] [ 3 ] Bug #2409791 - CVE-2025-61723 kustomize: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] [ 4 ] Bug #2410741 - CVE-2025-58185 kustomize: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] [ 5 ] Bug #2411637 - CVE-2025-58188 kustomize: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ecfd96d6a3' at the command line. For more information, refer to the dnf documentation available at