SUSE-SU-2025:03525-1

    Dashboard / Vulnerabilities / SUSE-SU-2025:03525-1

    SUSE-SU-2025:03525-1

    Published: 10 Oct 2025Last Modified: 23 Mar 2026
    Upstream:

    Summary: Security update for go1.25-openssl

    Details: This update for go1.25-openssl fixes the following issues: Update to version 1.25.1, released 2025-09-03 (bsc#1244485). Security issues fixed: - CVE-2025-47910: net/http: `CrossOriginProtection` insecure bypass patterns not limited to exact matches (bsc#1249141). Other issues fixed: - go#74822 cmd/go: 'get toolchain@latest' should ignore release candidates - go#74999 net: WriteMsgUDPAddrPort should accept IPv4-mapped IPv6 destination addresses on IPv4 UDP sockets - go#75008 os/exec: TestLookPath fails on plan9 after CL 685755 - go#75021 testing/synctest: bubble not terminating - go#75083 os: File.Seek doesn't set the correct offset with Windows overlapped handles

    Affected packages

    Package

    Name: go1.25-openssl

    Purl: pkg:rpm/suse/go1.25-openssl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP6

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.25.1-150600.13.6.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2025:03525-1 | CVE-DB