Resource exhaustion in go-git - CVE-2025-21614
Published: January 29, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling responses from a malicious Git server. A remote attacker can trick the victim into connecting to a malicious Git server and perform a denial of service (DoS) attack.
Affected software
IBM Concert Software
IBM Observability with Instana
IBM Cloud Pak for Security
APEX Cloud Platform for Red Hat OpenShift
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
Guardium Data Security Center (GDSC)
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Business Automation Insights
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Ubuntu
OpenShift Service Mesh
Red Hat OpenShift Container Platform
golang-github-go-git-go-git (Ubuntu package)
grafana (Red Hat package)
grafana-selinux
grafana
How to mitigate CVE-2025-21614
IBM Concert Software - update to 1.1.0
Guardium Data Security Center (GDSC) - update to 3.8.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Observability with Instana - update to 289
IBM Cloud Pak for Security - update to 1.11.2.0
OpenShift Service Mesh - addressed in versions 2.4.14, 2.5.8, 2.6.5
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.8, 4.5.6, 4.6.2
Red Hat OpenShift Container Platform - addressed in versions 4.17.14, 4.17.16
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.1
golang-github-go-git-go-git (Ubuntu package) - addressed in versions 5.4.2-3ubuntu0.1~esm1, 5.4.2-4ubuntu0.24.04.3+esm2
grafana (Red Hat package) - addressed in versions 9.2.10-21.el8_10, 9.2.10-21.el9_4
grafana-selinux - update to 9.2.10-21.0.1
grafana - update to 9.2.10-21.0.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
External References
Related Security Bulletins
- Multiple vulnerabilities in go-git
- Red Hat Enterprise Linux 8 update for grafana
- Red Hat Enterprise Linux 9 update for grafana
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.6
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for go-git
- Multiple vulnerabilities in IBM Instana Observability
- Anolis OS update for grafana
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
- Ubuntu update for golang-github-go-git-go-git