Protection Mechanism Failure in Go programming language - CVE-2025-22874
Published: June 7, 2025
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an error in crypto/x509 when using ExtKeyUsageAny. When calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny it disables policy validation.
This only affected certificate chains which contain policy graphs, which are rather uncommon.
Affected software
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
Development Tools Module
openSUSE Leap
Anolis OS
IBM Observability with Instana
Netcool Operations Insight
IT Service Intelligence (ITSI)
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
Splunk Operator for Kubernetes Add-on
IBM MQ Operator
App Connect Enterprise Certified Container
WatsonX BI Assistant
Maximo Application Suite - Visual Inspection Component
Robotic Process Automation for Cloud Pak
Business Automation Insights
Splunk Enterprise
IBM API Connect
golang-tests
golang-src
golang-misc
golang-docs
golang-shared
golang-bin
golang
go1.24-doc
go1.24-race
go1.24
go1.24-openssl-debuginfo
go1.24-openssl
go1.24-openssl-doc
go1.24-openssl-race
How to mitigate CVE-2025-22874
IBM Observability with Instana - update to 1.0.302
Netcool Operations Insight - update to 1.6.15
IT Service Intelligence (ITSI) - update to 4.21.2
WatsonX BI Assistant - update to 5.2.2
IBM Maximo Application Suite - addressed in versions 8.10.33, 8.11.30, 9.0.19, 9.1.8
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1
Maximo Application Suite - Visual Inspection Component - update to 9.0.11
IBM API Connect - update to 10.0.8.5
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.4, 30.0.0.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
golang-tests - update to 1.24.0-9
golang-src - update to 1.24.0-9
golang-misc - update to 1.24.0-9
golang-docs - update to 1.24.0-9
golang-shared - update to 1.24.0-9
golang-bin - update to 1.24.0-9
golang - update to 1.24.0-9
go1.24-doc - update to 1.24.4-150000.1.26.1
go1.24-race - update to 1.24.4-150000.1.26.1
go1.24 - update to 1.24.4-150000.1.26.1
go1.24-openssl-debuginfo - update to 1.24.6-150600.13.9.1
go1.24-openssl - update to 1.24.6-150600.13.9.1
go1.24-openssl-doc - update to 1.24.6-150600.13.9.1
go1.24-openssl-race - update to 1.24.6-150600.13.9.1
Splunk Operator for Kubernetes Add-on - update to 3.1.0
IBM MQ Operator - addressed in versions 3.2.16, 3.6.3, 9.4.3.1-r2
App Connect Enterprise Certified Container - addressed in versions 12.0.14, 12.14.0
External References
Related Security Bulletins
- Multiple vulnerabilities in Go programming language
- SUSE update for go1.24
- Protection mechanism failure in IBM App Connect Enterprise Certified Container
- SUSE update for go1.24-openssl
- Protection Mechanism Failure in IBM Maximo Application Suite - Visual Inspection Component
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Anolis OS update for golang
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM WatsonX BI Assistant for CP4D
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Splunk Enterprise Security update for third-party components
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in Splunk Enterprise
- Splunk Operator for Kubernetes Add-on update for third-party components
- Splunk IT Service Intelligence update for third-party components