Out-of-bounds read in crypto - CVE-2025-47914
Published: December 29, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary condition when processing new identity requests in SSH Agent servers. A remote attacker can send specially crafted GSSAPI authentication requests to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Micro
SUSE Enterprise Storage
Containers Module
HPC Module
openSUSE Leap
openEuler
Fusion Content-Aware Storage
watsonx Orchestrate Developer Edition
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Storage Protect Server
Maximo Application Suite - Visual Inspection Component
watsonx.data
IBM Cloud Pak System
IBM Fusion HCI
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Splunk Operator for Kubernetes Add-on
Splunk Enterprise
squashfuse-tools
squashfuse-devel
squashfuse-tools-debuginfo
squashfuse-debuginfo
squashfuse
libsquashfuse0-debuginfo
squashfuse-debugsource
libsquashfuse0
apptainer-sle16
apptainer-sle15_7
apptainer-leap
apptainer-sle15_6
apptainer-debuginfo
apptainer
elemental-support
elemental-register
buildah-debugsource
buildah-debuginfo
buildah
buildah-tests
elemental-toolkit
podman-remote-debuginfo
podman
podmansh
podman-remote
podman-docker
podman-debuginfo
How to mitigate CVE-2025-47914
Fusion Content-Aware Storage - update to 1.1.0
watsonx Orchestrate Developer Edition - update to 2.3.0
watsonx.data - update to 2.3.1
IBM Cloud Pak System - update to 2.3.5.1
IBM Fusion HCI - update to 2.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 2
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
Storage Protect Server - update to 8.2.1
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.18, 9.0.15, 9.1.5
Splunk Enterprise - addressed in versions 9.3.10, 9.4.9, 10.0.4, 10.2.1
squashfuse-tools - update to 0.5.0-150600.3.2.1
squashfuse-devel - update to 0.5.0-150600.3.2.1
squashfuse-tools-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse - update to 0.5.0-150600.3.2.1
libsquashfuse0-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-debugsource - update to 0.5.0-150600.3.2.1
libsquashfuse0 - update to 0.5.0-150600.3.2.1
apptainer-sle16 - update to 1.4.5-150600.4.12.1
apptainer-sle15_7 - update to 1.4.5-150600.4.12.1
apptainer-leap - update to 1.4.5-150600.4.12.1
apptainer-sle15_6 - update to 1.4.5-150600.4.12.1
apptainer-debuginfo - update to 1.4.5-150600.4.12.1
apptainer - update to 1.4.5-150600.4.12.1
elemental-support - update to 1.8.1-160000.1.1
elemental-register - update to 1.8.1-160000.1.1
buildah-debugsource - addressed in versions 1.26.1-13, 1.34.1-15
buildah-debuginfo - addressed in versions 1.26.1-13, 1.34.1-15
buildah - addressed in versions 1.26.1-13, 1.34.1-15
buildah-tests - update to 1.34.1-15
buildah - addressed in versions 1.35.5-150400.3.59.1, 1.35.5-150500.3.53.1
elemental-toolkit - update to 2.3.2-160000.1.1
Splunk Operator for Kubernetes Add-on - update to 3.1.0
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.69.1, 4.9.5-150400.4.65.2, 4.9.5-150500.3.62.2
podman - addressed in versions 4.9.5-150300.9.69.1, 4.9.5-150400.4.65.2, 4.9.5-150500.3.62.2
podmansh - addressed in versions 4.9.5-150300.9.69.1, 4.9.5-150400.4.65.2, 4.9.5-150500.3.62.2
podman-remote - addressed in versions 4.9.5-150300.9.69.1, 4.9.5-150400.4.65.2, 4.9.5-150500.3.62.2
podman-docker - addressed in versions 4.9.5-150300.9.69.1, 4.9.5-150400.4.65.2, 4.9.5-150500.3.62.2
podman-debuginfo - addressed in versions 4.9.5-150300.9.69.1, 4.9.5-150400.4.65.2, 4.9.5-150500.3.62.2
External References
Related Security Bulletins
- Denial of service in Go crypto ssh agent
- SUSE update for buildah
- SUSE update for podman
- SUSE update for buildah
- SUSE update for podman
- SUSE update for podman
- Multiple vulnerabilities in Splunk Enterprise
- SUSE update for apptainer
- SUSE update for elemental-register, elemental-toolkit
- Multiple vulnerabilities in IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in IBM Maximo Application Suite - Visual Inspection Component
- Multiple vulnerabilities in IBM watsonx Orchestrate Developer Edition
- Multiple vulnerabilities in IBM Storage Protect Server
- IBM Watson Speech Services Cartridge update for Golang Go
- Splunk Operator for Kubernetes Add-on update for third-party components
- Multiple vulnerabilities in IBM Cloud Pak System
- openEuler 24.03 LTS SP4 update for buildah
- openEuler 24.03 LTS SP3 update for buildah
- openEuler 24.03 LTS SP1 update for buildah
- openEuler 22.03 LTS SP4 update for buildah
- Multiple vulnerabilities in IBM Fusion, IBM Fusion HCI, and IBM Fusion Content-Aware Storage