-
Vulnerability
-
Resolution: Done
-
Critical
-
ACM 2.13.0
-
Security & Compliance
-
False
-
-
False
-
-
-
Critical
-
None
Description of problem:
Denial of Service in the Key Exchange of golang.org/x/crypto/ssh
https://docs.google.com/spreadsheets/d/1UqwOA6KAhfS2NtMGRk6og8EuUh3up9iPxLxDKPuflGw/edit?gid=1743374624#gid=1743374624
Affected business continuity repos:
- volsync-addon-controller
- clones
-
ACM-19397 CVE-2025-22868 Unexpected memory consumption during token parsing in golang.org/x/oauth2 for business continuity no tracker components
-
- Resolved
-
- is cloned by
-
ACM-19417 CVE-2025-22869 for business continuity no tracker components [rhacm-2.12.z]
-
- Resolved
-
-
ACM-19420 [ACM 2.11.z] CVE-2025-22869 for business continuity no tracker components
-
- Resolved
-
-
ACM-19422 [ACM 2.10.z CVE-2025-22869 for business continuity no tracker components
-
- Resolved
-
-
ACM-19504 [ACM 2.9.z] CVE-2025-22869 for business continuity no tracker components
-
- Resolved
-