Protection Mechanism Failure in Go programming language - CVE-2025-22874

 

Protection Mechanism Failure in Go programming language - CVE-2025-22874

Published: June 7, 2025


Vulnerability identifier: #VU110253
CSH Severity: Low
CVSS v4 BT: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-22874
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an error in crypto/x509 when using ExtKeyUsageAny. When calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny it disables policy validation.

This only affected certificate chains which contain policy graphs, which are rather uncommon.


Affected software

Go programming language
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
Development Tools Module
openSUSE Leap
Anolis OS
IBM Observability with Instana
Netcool Operations Insight
IT Service Intelligence (ITSI)
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
Splunk Operator for Kubernetes Add-on
IBM MQ Operator
App Connect Enterprise Certified Container
WatsonX BI Assistant
Maximo Application Suite - Visual Inspection Component
Robotic Process Automation for Cloud Pak
Business Automation Insights
Splunk Enterprise
IBM API Connect
golang-tests
golang-src
golang-misc
golang-docs
golang-shared
golang-bin
golang
go1.24-doc
go1.24-race
go1.24
go1.24-openssl-debuginfo
go1.24-openssl
go1.24-openssl-doc
go1.24-openssl-race

How to mitigate CVE-2025-22874

Install updates from vendor's website.

Go programming language - update to 1.24.4
IBM Observability with Instana - update to 1.0.302
Netcool Operations Insight - update to 1.6.15
IT Service Intelligence (ITSI) - update to 4.21.2
WatsonX BI Assistant - update to 5.2.2
IBM Maximo Application Suite - addressed in versions 8.10.33, 8.11.30, 9.0.19, 9.1.8
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1
Maximo Application Suite - Visual Inspection Component - update to 9.0.11
IBM API Connect - update to 10.0.8.5
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.4, 30.0.0.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
golang-tests - update to 1.24.0-9
golang-src - update to 1.24.0-9
golang-misc - update to 1.24.0-9
golang-docs - update to 1.24.0-9
golang-shared - update to 1.24.0-9
golang-bin - update to 1.24.0-9
golang - update to 1.24.0-9
go1.24-doc - update to 1.24.4-150000.1.26.1
go1.24-race - update to 1.24.4-150000.1.26.1
go1.24 - update to 1.24.4-150000.1.26.1
go1.24-openssl-debuginfo - update to 1.24.6-150600.13.9.1
go1.24-openssl - update to 1.24.6-150600.13.9.1
go1.24-openssl-doc - update to 1.24.6-150600.13.9.1
go1.24-openssl-race - update to 1.24.6-150600.13.9.1
Splunk Operator for Kubernetes Add-on - update to 3.1.0
IBM MQ Operator - addressed in versions 3.2.16, 3.6.3, 9.4.3.1-r2
App Connect Enterprise Certified Container - addressed in versions 12.0.14, 12.14.0

External References

Related Security Bulletins