Resource exhaustion in go-jose - CVE-2025-27144

 

Resource exhaustion in go-jose - CVE-2025-27144

Published: March 7, 2025


Vulnerability identifier: #VU105450
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27144
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when parsing JWS and JWE input. A remote attacker can pass specially crafted data to the application, trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

go-jose
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
Containers Module
HPC Module
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
IBM Concert Software
IBM Cloud Pak for Security
cert-manager Operator for Red Hat OpenShift
Red Hat Advanced Cluster Management for Kubernetes
Splunk User Behavior Analytics (UBA)
IBM Cloud Pak for Business Automation
IBM Observability with Instana
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
QRadar Suite
Storage Fusion Data Foundation
Business Automation Insights
APEX Cloud Platform for Microsoft Azure
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
squashfuse-debuginfo
squashfuse-tools-debuginfo
squashfuse-devel
squashfuse-tools
squashfuse
libsquashfuse0-debuginfo
squashfuse-debugsource
libsquashfuse0
opentelemetry-collector (Red Hat package)
skopeo-debugsource
skopeo-debuginfo
containers-common
skopeo
apptainer-sle15_7
apptainer-leap
apptainer-sle15_6
apptainer-sle15_5
apptainer
apptainer-debuginfo
rekor-debuginfo
rekor
podman-tui
apptainer-sle16
skopeo-tests
skopeo-bash-completion
skopeo-zsh-completion
skopeo-fish-completion
prometheus-podman-exporter
skopeo (Red Hat package)
crun (Red Hat package)
buildah
buildah-debugsource
buildah-debuginfo
cri-o1.31
buildah-tests
buildah (Red Hat package)
cosign
cosign-debuginfo
cosign-bash-completion
cosign-fish-completion
cosign-zsh-completion
gh
podman-remote-debuginfo
podmansh
podman-remote
podman
podman-debuginfo
podman-docker
libreswan (Red Hat package)
podman (Red Hat package)
kernel (Red Hat package)
incus
grafana
grafana-debuginfo
osbuild-composer-core
osbuild-composer
osbuild-composer-worker
osbuild-composer (Red Hat package)
OpenShift API for Data Protection (OADP)
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform

How to mitigate CVE-2025-27144

Install updates from vendor's website.

go-jose - addressed in versions 3.0.4, 4.0.5
IBM Concert Software - update to 1.1.0
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.5
Splunk User Behavior Analytics (UBA) - update to 5.4.3
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
squashfuse-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-tools-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-devel - update to 0.5.0-150600.3.2.1
squashfuse-tools - update to 0.5.0-150600.3.2.1
squashfuse - update to 0.5.0-150600.3.2.1
libsquashfuse0-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-debugsource - update to 0.5.0-150600.3.2.1
libsquashfuse0 - update to 0.5.0-150600.3.2.1
opentelemetry-collector (Red Hat package) - update to 0.107.0-7.el9_4
IBM Observability with Instana - update to 1.0.295
skopeo-debugsource - addressed in versions 1.1.0-13, 1.8.0-7, 1.14.2-6
skopeo-debuginfo - addressed in versions 1.1.0-13, 1.8.0-7, 1.14.2-6
containers-common - update to 1.1.0-13
skopeo - addressed in versions 1.1.0-13, 1.8.0-7, 1.14.2-6
apptainer-sle15_7 - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-leap - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-sle15_6 - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-sle15_5 - update to 1.3.6-150600.4.9.1
apptainer - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-debuginfo - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
rekor-debuginfo - update to 1.3.10-150400.4.25.1
rekor - update to 1.3.10-150400.4.25.1
podman-tui - addressed in versions 1.4.0-1.el9, 1.4.0-1.el10_1, 1.4.0-1.fc40, 1.4.0-1.fc41, 1.4.0-1.fc42
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
OpenShift API for Data Protection (OADP) - update to 1.4.5
apptainer-sle16 - update to 1.4.5-150600.4.12.1
skopeo-tests - update to 1.14.2-6
skopeo-bash-completion - update to 1.14.4-150300.11.19.1
skopeo-zsh-completion - update to 1.14.4-150300.11.19.1
skopeo-fish-completion - update to 1.14.4-150300.11.19.1
skopeo - update to 1.14.4-150300.11.19.1
skopeo-debuginfo - update to 1.14.4-150300.11.19.1
prometheus-podman-exporter - addressed in versions 1.16.0-1.el9, 1.16.0-1.fc41, 1.16.0-1.fc42
skopeo (Red Hat package) - addressed in versions 1.16.1-1.rhaos4.17.el8, 1.16.1-1.rhaos4.17.el9, 1.16.1-1.rhaos4.18.el9
crun (Red Hat package) - update to 1.20-2.rhaos4.18.el9
buildah - addressed in versions 1.26.1-7, 1.34.1-7, 1.34.1-10
buildah-debugsource - addressed in versions 1.26.1-7, 1.34.1-7, 1.34.1-10
buildah-debuginfo - addressed in versions 1.26.1-7, 1.34.1-7, 1.34.1-10
cri-o1.31 - update to 1.31.7-1.fc43
buildah-tests - addressed in versions 1.34.1-7, 1.34.1-10
buildah - addressed in versions 1.35.5-150300.8.36.1, 1.35.5-150300.8.39.1, 1.35.5-150400.3.42.1, 1.35.5-150400.3.45.1, 1.35.5-150500.3.31.1, 1.35.5-150500.3.34.1
buildah - update to 1.39.2-1.fc41
buildah (Red Hat package) - update to 1.39.4-1.el9_6
cosign - update to 2.5.0-150400.3.27.1
cosign-debuginfo - update to 2.5.0-150400.3.27.1
cosign-bash-completion - update to 2.5.0-150400.3.27.1
cosign-fish-completion - update to 2.5.0-150400.3.27.1
cosign-zsh-completion - update to 2.5.0-150400.3.27.1
Multicluster Engine for Kubernetes - addressed in versions 2.7.4, 2.8.1
gh - update to 2.72.0-1.fc43
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Red Hat OpenShift Dev Spaces - update to 3.20.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.17.7
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.6.4, 4.7.1
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
podmansh - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
podman-remote - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
podman - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
podman-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
podman-docker - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
Red Hat OpenShift Container Platform - addressed in versions 4.16.38, 4.17.22, 4.17.23, 4.17.30, 4.18.6, 4.18.9, 4.18.11, 4.18.12, 4.18.13, 4.19.0
libreswan (Red Hat package) - update to 5.2-1.el9fdp
podman (Red Hat package) - addressed in versions 5.2.2-4.rhaos4.17.el8, 5.2.2-4.rhaos4.17.el9, 5.2.2-6.rhaos4.18.el9, 5.4.0-9.el9_6
OpenShift Logging - addressed in versions 5.9.13, 6.0.6, 6.1.4
kernel (Red Hat package) - update to 5.14.0-427.61.1.el9_4
incus - addressed in versions 6.12-1.fc41, 6.12-1.fc42
grafana - addressed in versions 10.4.15-1.75.1, 10.4.15-150000.1.75.1, 10.4.15-150200.3.67.1, 10.4.15-150200.3.69.1
grafana-debuginfo - addressed in versions 10.4.15-150000.1.75.1, 10.4.15-150200.3.67.1, 10.4.15-150200.3.69.1
osbuild-composer-core - update to 132.2-3.0.1
osbuild-composer - update to 132.2-3.0.1
osbuild-composer-worker - update to 132.2-3.0.1
osbuild-composer (Red Hat package) - update to 134.1-3.el10_0

External References

Related Security Bulletins