Resource exhaustion in go-git - CVE-2025-21614

 

Resource exhaustion in go-git - CVE-2025-21614

Published: January 29, 2025


Vulnerability identifier: #VU103422
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-21614
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling responses from a malicious Git server. A remote attacker can trick the victim into connecting to a malicious Git server and perform a denial of service (DoS) attack.


Affected software

go-git
IBM Concert Software
IBM Observability with Instana
IBM Cloud Pak for Security
APEX Cloud Platform for Red Hat OpenShift
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
Guardium Data Security Center (GDSC)
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Business Automation Insights
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Ubuntu
OpenShift Service Mesh
Red Hat OpenShift Container Platform
golang-github-go-git-go-git (Ubuntu package)
grafana (Red Hat package)
grafana-selinux
grafana

How to mitigate CVE-2025-21614

Install updates from vendor's website.

go-git - update to 5.13.0
IBM Concert Software - update to 1.1.0
Guardium Data Security Center (GDSC) - update to 3.8.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Observability with Instana - update to 289
IBM Cloud Pak for Security - update to 1.11.2.0
OpenShift Service Mesh - addressed in versions 2.4.14, 2.5.8, 2.6.5
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.8, 4.5.6, 4.6.2
Red Hat OpenShift Container Platform - addressed in versions 4.17.14, 4.17.16
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.1
golang-github-go-git-go-git (Ubuntu package) - addressed in versions 5.4.2-3ubuntu0.1~esm1, 5.4.2-4ubuntu0.24.04.3+esm2
grafana (Red Hat package) - addressed in versions 9.2.10-21.el8_10, 9.2.10-21.el9_4
grafana-selinux - update to 9.2.10-21.0.1
grafana - update to 9.2.10-21.0.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001

External References

Related Security Bulletins