Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-62651

Update the dependency "xz" package to version '0.5.15' to fix CVE-2025-58058

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • 4.16.z
    • oc
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Moderate
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      The scanner reports that cve [1] is affecting the oc cli binary with the dependency package "xz" at version 0.5.11. [2]
      
      Requesting The version '0.5.15' of the "xz" should contain the fix for the cve.
      The cve report came from the ACS scanner.
      
      Other versions affected - [3][4][5]
      
      [1] https://access.redhat.com/security/cve/cve-2025-58058 
      [2] https://github.com/openshift/oc/blob/release-4.16/go.mod#L179
      [3] https://github.com/openshift/oc/blob/release-4.17/go.mod#L183
      [4] https://github.com/openshift/oc/blob/release-4.18/go.mod#L182
      [5] https://github.com/openshift/oc/blob/release-4.19/go.mod#L179

      Version-Release number of selected component (if applicable):

      OpenShift Container Platform 4.16.z 

       

              aos-workloads-staff Workloads Team Bot Account
              rhn-support-vwalek Vladislav Walek
              None
              None
              Ying Zhou Ying Zhou
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: