Resource exhaustion in go-jose - CVE-2025-27144
Published: March 7, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing JWS and JWE input. A remote attacker can pass specially crafted data to the application, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
Containers Module
HPC Module
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
IBM Concert Software
IBM Cloud Pak for Security
cert-manager Operator for Red Hat OpenShift
Red Hat Advanced Cluster Management for Kubernetes
Splunk User Behavior Analytics (UBA)
IBM Cloud Pak for Business Automation
IBM Observability with Instana
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
QRadar Suite
Storage Fusion Data Foundation
Business Automation Insights
APEX Cloud Platform for Microsoft Azure
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
squashfuse-debuginfo
squashfuse-tools-debuginfo
squashfuse-devel
squashfuse-tools
squashfuse
libsquashfuse0-debuginfo
squashfuse-debugsource
libsquashfuse0
opentelemetry-collector (Red Hat package)
skopeo-debugsource
skopeo-debuginfo
containers-common
skopeo
apptainer-sle15_7
apptainer-leap
apptainer-sle15_6
apptainer-sle15_5
apptainer
apptainer-debuginfo
rekor-debuginfo
rekor
podman-tui
apptainer-sle16
skopeo-tests
skopeo-bash-completion
skopeo-zsh-completion
skopeo-fish-completion
prometheus-podman-exporter
skopeo (Red Hat package)
crun (Red Hat package)
buildah
buildah-debugsource
buildah-debuginfo
cri-o1.31
buildah-tests
buildah (Red Hat package)
cosign
cosign-debuginfo
cosign-bash-completion
cosign-fish-completion
cosign-zsh-completion
gh
podman-remote-debuginfo
podmansh
podman-remote
podman
podman-debuginfo
podman-docker
libreswan (Red Hat package)
podman (Red Hat package)
kernel (Red Hat package)
incus
grafana
grafana-debuginfo
osbuild-composer-core
osbuild-composer
osbuild-composer-worker
osbuild-composer (Red Hat package)
OpenShift API for Data Protection (OADP)
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
How to mitigate CVE-2025-27144
IBM Concert Software - update to 1.1.0
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.5
Splunk User Behavior Analytics (UBA) - update to 5.4.3
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
squashfuse-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-tools-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-devel - update to 0.5.0-150600.3.2.1
squashfuse-tools - update to 0.5.0-150600.3.2.1
squashfuse - update to 0.5.0-150600.3.2.1
libsquashfuse0-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-debugsource - update to 0.5.0-150600.3.2.1
libsquashfuse0 - update to 0.5.0-150600.3.2.1
opentelemetry-collector (Red Hat package) - update to 0.107.0-7.el9_4
IBM Observability with Instana - update to 1.0.295
skopeo-debugsource - addressed in versions 1.1.0-13, 1.8.0-7, 1.14.2-6
skopeo-debuginfo - addressed in versions 1.1.0-13, 1.8.0-7, 1.14.2-6
containers-common - update to 1.1.0-13
skopeo - addressed in versions 1.1.0-13, 1.8.0-7, 1.14.2-6
apptainer-sle15_7 - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-leap - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-sle15_6 - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-sle15_5 - update to 1.3.6-150600.4.9.1
apptainer - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-debuginfo - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
rekor-debuginfo - update to 1.3.10-150400.4.25.1
rekor - update to 1.3.10-150400.4.25.1
podman-tui - addressed in versions 1.4.0-1.el9, 1.4.0-1.el10_1, 1.4.0-1.fc40, 1.4.0-1.fc41, 1.4.0-1.fc42
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
OpenShift API for Data Protection (OADP) - update to 1.4.5
apptainer-sle16 - update to 1.4.5-150600.4.12.1
skopeo-tests - update to 1.14.2-6
skopeo-bash-completion - update to 1.14.4-150300.11.19.1
skopeo-zsh-completion - update to 1.14.4-150300.11.19.1
skopeo-fish-completion - update to 1.14.4-150300.11.19.1
skopeo - update to 1.14.4-150300.11.19.1
skopeo-debuginfo - update to 1.14.4-150300.11.19.1
prometheus-podman-exporter - addressed in versions 1.16.0-1.el9, 1.16.0-1.fc41, 1.16.0-1.fc42
skopeo (Red Hat package) - addressed in versions 1.16.1-1.rhaos4.17.el8, 1.16.1-1.rhaos4.17.el9, 1.16.1-1.rhaos4.18.el9
crun (Red Hat package) - update to 1.20-2.rhaos4.18.el9
buildah - addressed in versions 1.26.1-7, 1.34.1-7, 1.34.1-10
buildah-debugsource - addressed in versions 1.26.1-7, 1.34.1-7, 1.34.1-10
buildah-debuginfo - addressed in versions 1.26.1-7, 1.34.1-7, 1.34.1-10
cri-o1.31 - update to 1.31.7-1.fc43
buildah-tests - addressed in versions 1.34.1-7, 1.34.1-10
buildah - addressed in versions 1.35.5-150300.8.36.1, 1.35.5-150300.8.39.1, 1.35.5-150400.3.42.1, 1.35.5-150400.3.45.1, 1.35.5-150500.3.31.1, 1.35.5-150500.3.34.1
buildah - update to 1.39.2-1.fc41
buildah (Red Hat package) - update to 1.39.4-1.el9_6
cosign - update to 2.5.0-150400.3.27.1
cosign-debuginfo - update to 2.5.0-150400.3.27.1
cosign-bash-completion - update to 2.5.0-150400.3.27.1
cosign-fish-completion - update to 2.5.0-150400.3.27.1
cosign-zsh-completion - update to 2.5.0-150400.3.27.1
Multicluster Engine for Kubernetes - addressed in versions 2.7.4, 2.8.1
gh - update to 2.72.0-1.fc43
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Red Hat OpenShift Dev Spaces - update to 3.20.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.17.7
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.6.4, 4.7.1
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
podmansh - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
podman-remote - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
podman - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
podman-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
podman-docker - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150300.9.46.1, 4.9.5-150400.4.41.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.37.1, 4.9.5-150500.3.40.1
Red Hat OpenShift Container Platform - addressed in versions 4.16.38, 4.17.22, 4.17.23, 4.17.30, 4.18.6, 4.18.9, 4.18.11, 4.18.12, 4.18.13, 4.19.0
libreswan (Red Hat package) - update to 5.2-1.el9fdp
podman (Red Hat package) - addressed in versions 5.2.2-4.rhaos4.17.el8, 5.2.2-4.rhaos4.17.el9, 5.2.2-6.rhaos4.18.el9, 5.4.0-9.el9_6
OpenShift Logging - addressed in versions 5.9.13, 6.0.6, 6.1.4
kernel (Red Hat package) - update to 5.14.0-427.61.1.el9_4
incus - addressed in versions 6.12-1.fc41, 6.12-1.fc42
grafana - addressed in versions 10.4.15-1.75.1, 10.4.15-150000.1.75.1, 10.4.15-150200.3.67.1, 10.4.15-150200.3.69.1
grafana-debuginfo - addressed in versions 10.4.15-150000.1.75.1, 10.4.15-150200.3.67.1, 10.4.15-150200.3.69.1
osbuild-composer-core - update to 132.2-3.0.1
osbuild-composer - update to 132.2-3.0.1
osbuild-composer-worker - update to 132.2-3.0.1
osbuild-composer (Red Hat package) - update to 134.1-3.el10_0
External References
Related Security Bulletins
- Denial of service in go-jose
- Fedora EPEL 9 update for podman-tui
- Fedora EPEL 10.1 update for podman-tui
- Fedora 40 update for podman-tui
- Fedora 41 update for podman-tui
- Fedora 42 update for podman-tui
- Fedora 41 update for buildah
- SUSE update for skopeo
- SUSE update for podman
- SUSE update for podman
- SUSE update for podman
- SUSE update for buildah
- SUSE update for buildah
- SUSE update for buildah
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Resource exhaustion in Red Hat OpenShift Container Platform 4.18 packages
- SUSE update for grafana
- SUSE update for grafana
- SUSE update for grafana
- SUSE update for buildah
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- SUSE update for buildah
- SUSE update for buildah
- Multiple vulnerabilities in OpenShift Logging 6.0
- Multiple vulnerabilities in OpenShift Logging 6.1
- Resource exhaustion in Red Hat OpenShift Container Platform 4.17 packages
- SUSE update for podman
- SUSE update for podman
- SUSE update for podman
- SUSE update for apptainer
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Fedora 43 update for cri-o1.31
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.8
- Fedora EPEL 9 update for prometheus-podman-exporter
- Fedora 41 update for prometheus-podman-exporter
- Fedora 42 update for prometheus-podman-exporter
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.20
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- SUSE update for rekor
- SUSE update for cosign
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Fedora 41 update for incus
- Fedora 42 update for incus
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for podman
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in IBM Cloud Pak for Security and IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- IBM Storage Fusion Data Foundation update for Go JOSE
- Multiple vulnerabilities in OpenShift Logging 5.9
- Red Hat Enterprise Linux 9 update for opentelemetry-collector
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.4
- Splunk User Behavior Analytics (UBA) update for third-party components
- openEuler 24.03 LTS SP1 update for skopeo
- openEuler 22.03 LTS SP4 update for skopeo
- openEuler 22.03 LTS SP3 update for skopeo
- openEuler 20.03 LTS SP4 update for skopeo
- openEuler 24.03 LTS SP2 update for skopeo
- openEuler 24.03 LTS SP2 update for buildah
- openEuler 24.03 LTS SP1 update for buildah
- openEuler 24.03 LTS update for buildah
- openEuler 24.03 LTS update for skopeo
- openEuler 22.03 LTS SP4 update for buildah
- Red Hat Enterprise Linux 10 update for osbuild-composer
- Anolis OS update for osbuild-composer
- Multiple vulnerabilities in IBM Business Automation Insights
- cert-manager Operator for Red Hat OpenShift update for go-jose
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.13
- SUSE update for apptainer
- Fedora 43 update for gh