Resource exhaustion in crypto - CVE-2025-22869

 

Resource exhaustion in crypto - CVE-2025-22869

Published: March 10, 2025


Vulnerability identifier: #VU105459
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22869
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the ssh package when handling clients that complete the key exchange slowly, or not at all. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

crypto
Security Verify Access OIDC Provider
Db2 Intelligence Center
DB2 Data Management Console
Guardium Data Security Center (GDSC)
Security QRadar EDR
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Storage Fusion Data Foundation
DevOps Solution Workbench
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Maximo Application Suite - Visual Inspection Component
Verify Identity Access Digital Credentials
Robotic Process Automation for Cloud Pak
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Storage Protect Server
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
Oracle Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Public Cloud Module
HPC Module
Containers Module
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
VolSync
IBM Concert Software
Netcool Operations Insight
IBM Cloud Pak for Security
IBM Fusion HCI
Splunk User Behavior Analytics (UBA)
IBM Observability with Instana
Multicluster GlobalHub
Red Hat Advanced Cluster Management for Kubernetes
APEX Cloud Platform for Red Hat OpenShift
AI Inference Server
AI Inference Server Model Optimization Tools
IBM MQ Operator
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
QRadar Suite
Juniper Secure Analytics (JSA)
Splunk Enterprise
watsonx.data
IBM Cloud Pak System
Cloud Pak for Data
IBM Qradar SIEM
Event Streams
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-go.crypto (Ubuntu package)
toolbox-tests
toolbox
govulncheck-vulndb
udica
libsquashfuse0
squashfuse-debugsource
libsquashfuse0-debuginfo
squashfuse
squashfuse-debuginfo
squashfuse-tools-debuginfo
squashfuse-devel
squashfuse-tools
gvisor-tap-vsock (Red Hat package)
restic
runc
slirp4netns
oci-seccomp-bpf-hook
apptainer-sle15_6
apptainer-leap
apptainer-sle15_7
apptainer-sle15_5
apptainer
apptainer-debuginfo
rekor
rekor-debuginfo
containernetworking-plugins
apptainer-sle16
podman-tui
opentofu
aardvark-dns
netavark
fuse-overlayfs
terraform-provider-kubernetes
crun
skopeo
skopeo-tests
prometheus-podman-exporter
buildah
buildah-debuginfo
buildah-debugsource
buildah-tests
rclone
containers-common
doctl
terraform-provider-external
terraform-provider-local
conmon
elemental-toolkit
cosign-debuginfo
cosign
cosign-fish-completion
cosign-bash-completion
cosign-zsh-completion
terraform-provider-helm
caddy
terraform-provider-azurerm
gh
container-selinux
terraform-provider-tls
terraform-provider-random
terraform-provider-aws
python3-criu
criu-libs
criu-devel
criu
crit
terraform-provider-google
podman (Red Hat package)
libslirp
libslirp-devel
warewulf4-dracut
warewulf4
warewulf4-overlay
warewulf4-man
warewulf4-overlay-slurm
warewulf4-overlay-rke2
warewulf4-reference-doc
python3-podman
podman-docker
podman-tests
podman-remote
podman-plugins
podman
podman-catatonit
podman-gvproxy
podman-debuginfo
podmansh
podman-remote-debuginfo
incus
docker-stable-bash-completion
docker-stable-debuginfo
docker-stable
docker-stable-fish-completion
docker-stable-zsh-completion
docker-stable-rootless-extras
docker
docker-debuginfo
docker-bash-completion
docker-zsh-completion
docker-rootless-extras
docker-fish-completion
cockpit-podman
Splunk Universal Forwarder
IBM Security Verify Access
Orion Platform
OpenShift API for Data Protection (OADP)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform

How to mitigate CVE-2025-22869

Install updates from vendor's website.

crypto - update to 0.35.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.0
VolSync - update to 0.12.1
IBM Concert Software - update to 1.1.0
Db2 Intelligence Center - update to 1.1.1.0
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
IBM Fusion HCI - update to 2.11.0
watsonx.data - update to 2.2.1
IBM Cloud Pak System - update to 2.3.6.0
DB2 Data Management Console - update to 3.1.13.2
Guardium Data Security Center (GDSC) - update to 3.7.2
Security QRadar EDR - update to 3.12.17
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.1
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.1.3
Cloud Pak for Data - update to 5.2.0
Splunk User Behavior Analytics (UBA) - update to 5.4.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP12 IF03
Splunk Universal Forwarder - addressed in versions 9.1.9, 9.2.6, 9.3.4, 9.4.2
Maximo Application Suite - Visual Inspection Component - update to 9.1.1
Splunk Enterprise - addressed in versions 9.1.9, 9.2.6, 9.3.4, 9.4.2
Event Streams - update to 12.2.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.3
Orion Platform - update to 2025.2
golang-go.crypto (Ubuntu package) - addressed in versions 1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm3, 1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm3, 1:0.0~git20200221.2aa609c-1ubuntu0.1~esm3, 1:0.0~git20211202.5770296-1ubuntu0.1~esm3, 1:0.19.0-1ubuntu0.1~esm3, 1:0.25.0-1ubuntu0.1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
govulncheck-vulndb - update to 0.0.20250226T025151-150000.1.35.1
udica - update to 0.2.6-21
libsquashfuse0 - update to 0.5.0-150600.3.2.1
squashfuse-debugsource - update to 0.5.0-150600.3.2.1
libsquashfuse0-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse - update to 0.5.0-150600.3.2.1
squashfuse-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-tools-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-devel - update to 0.5.0-150600.3.2.1
squashfuse-tools - update to 0.5.0-150600.3.2.1
gvisor-tap-vsock (Red Hat package) - addressed in versions 0.7.3-5.el9_4.1, 0.8.5-1.el9_5, 0.8.5-1.el9_6
restic - update to 0.18.0-1.fc43
IBM Observability with Instana - update to 1.0.295
runc - update to 1.1.12-6.0.1
Multicluster GlobalHub - addressed in versions 1.2.2, 1.3.3
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
apptainer-sle15_6 - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-leap - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-sle15_7 - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-sle15_5 - update to 1.3.6-150600.4.9.1
apptainer - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-debuginfo - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
rekor - update to 1.3.10-150400.4.25.1
rekor-debuginfo - update to 1.3.10-150400.4.25.1
containernetworking-plugins - update to 1.4.0-5.0.1
OpenShift API for Data Protection (OADP) - update to 1.4.5
apptainer-sle16 - update to 1.4.5-150600.4.12.1
podman-tui - addressed in versions 1.5.0-1.el10_1, 1.5.0-1.fc41, 1.5.0-1.fc42, 1.5.0-2.el9
opentofu - addressed in versions 1.9.1-1.fc43, 1.10.3-1.el9
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
terraform-provider-kubernetes - update to 1.13.2-150200.6.6.1
crun - update to 1.14.3-2
skopeo - update to 1.14.5-3.0.1
skopeo-tests - update to 1.14.5-3.0.1
prometheus-podman-exporter - addressed in versions 1.16.0-1.el9, 1.16.0-1.fc41, 1.16.0-1.fc42
buildah - addressed in versions 1.26.1-7, 1.34.1-7
buildah-debuginfo - addressed in versions 1.26.1-7, 1.34.1-7
buildah-debugsource - addressed in versions 1.26.1-7, 1.34.1-7
buildah - update to 1.33.12-1
buildah-tests - update to 1.33.12-1
buildah-tests - update to 1.34.1-7
buildah - addressed in versions 1.35.5-150300.8.39.1, 1.35.5-150400.3.45.1, 1.35.5-150500.3.34.1
rclone - addressed in versions 1.70.2-1.fc43, 1.70.3-1.el9
containers-common - update to 1-82.0.1
doctl - update to 1.132.0-1.fc43
terraform-provider-external - update to 2.0.0-150200.6.6.1
terraform-provider-local - update to 2.0.0-150200.6.11.1
conmon - update to 2.1.10-1
elemental-toolkit - update to 2.2.3-slfo.1.1_1.1
cosign-debuginfo - update to 2.5.0-150400.3.27.1
cosign - update to 2.5.0-150400.3.27.1
cosign-fish-completion - update to 2.5.0-150400.3.27.1
cosign-bash-completion - update to 2.5.0-150400.3.27.1
cosign-zsh-completion - update to 2.5.0-150400.3.27.1
terraform-provider-helm - update to 2.9.0-150200.6.17.1
caddy - addressed in versions 2.10.0-1.fc42, 2.10.0-1.fc43
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.10.8, 2.11.7, 2.12.3, 2.13.2
terraform-provider-azurerm - update to 2.32.0-150200.6.6.1
gh - update to 2.72.0-1.fc43
container-selinux - update to 2.229.0-2
terraform-provider-tls - update to 3.0.0-150200.5.9.1
terraform-provider-random - update to 3.0.0-150200.6.9.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
AI Inference Server - update to 3.2.5
AI Inference Server Model Optimization Tools - update to 3.2.5
IBM MQ Operator - addressed in versions 3.2.12, 3.5.3, 9.4.2.1-r2
terraform-provider-aws - update to 3.11.0-150200.6.12.1
python3-criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
Red Hat OpenShift Dev Spaces - addressed in versions 3.20.0, 3.21.0
terraform-provider-google - update to 3.43.0-150200.6.6.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4
podman (Red Hat package) - addressed in versions 4.2.0-6.el9_0.3, 4.4.1-22.el9_2.1, 4.9.4-18.el9_4, 5.4.0-9.el9_6
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.5.8, 4.6.4, 4.7.1
warewulf4-dracut - update to 4.6.0-150500.6.34.1
warewulf4 - update to 4.6.0-150500.6.34.1
warewulf4-overlay - update to 4.6.0-150500.6.34.1
warewulf4-man - update to 4.6.0-150500.6.34.1
warewulf4-overlay-slurm - update to 4.6.0-150500.6.34.1
warewulf4-overlay-rke2 - update to 4.6.0-150500.6.34.1
warewulf4-reference-doc - update to 4.6.0-150500.6.34.1
python3-podman - update to 4.9.0-3
podman-docker - update to 4.9.4-20.0.1
podman-tests - update to 4.9.4-20.0.1
podman-remote - update to 4.9.4-20.0.1
podman-plugins - update to 4.9.4-20.0.1
podman - update to 4.9.4-20.0.1
podman-catatonit - update to 4.9.4-20.0.1
podman-gvproxy - update to 4.9.4-20.0.1
podman-docker - addressed in versions 4.9.5-150300.9.46.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.40.1
podman-debuginfo - addressed in versions 4.9.5-150300.9.46.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.40.1
podmansh - addressed in versions 4.9.5-150300.9.46.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.40.1
podman - addressed in versions 4.9.5-150300.9.46.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.40.1
podman-remote - addressed in versions 4.9.5-150300.9.46.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.40.1
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.46.1, 4.9.5-150400.4.44.1, 4.9.5-150500.3.40.1
Red Hat OpenShift Container Platform - addressed in versions 4.14.52, 4.15.51, 4.16.38, 4.17.26, 4.19.0
watsonx Assistant Cartridge - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
incus - addressed in versions 6.12-1.fc41, 6.12-1.fc42
Storage Protect Server - update to 8.1.27.100
docker-stable-bash-completion - addressed in versions 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-debuginfo - addressed in versions 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable - addressed in versions 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-fish-completion - addressed in versions 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-zsh-completion - addressed in versions 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-rootless-extras - addressed in versions 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker - addressed in versions 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
docker-debuginfo - addressed in versions 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
docker-bash-completion - addressed in versions 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
docker-zsh-completion - update to 27.5.1_ce-150000.218.1
docker-rootless-extras - update to 27.5.1_ce-150000.218.1
docker-fish-completion - update to 27.5.1_ce-150000.218.1
cockpit-podman - update to 84.1-1

External References

Related Security Bulletins