Resource exhaustion in crypto - CVE-2025-58181
Published: March 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing GSSAPI authentication requests. A remote attacker can send specially crafted GSSAPI authentication requests to the application, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Micro
HPC Module
Basesystem Module
Containers Module
openSUSE Leap
Ubuntu
openEuler
Fusion Content-Aware Storage
watsonx Orchestrate Developer Edition
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Storage Protect Server
Maximo Application Suite - Visual Inspection Component
watsonx.data
IBM Cloud Pak System
IBM Fusion HCI
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Splunk Operator for Kubernetes Add-on
Communications Unified Assurance
Splunk Enterprise
squashfuse-tools
libsquashfuse0
squashfuse-debugsource
libsquashfuse0-debuginfo
squashfuse
squashfuse-debuginfo
squashfuse-tools-debuginfo
squashfuse-devel
docker-buildx
docker-buildx-debuginfo
apptainer
apptainer-debuginfo
apptainer-sle16
apptainer-sle15_6
apptainer-leap
apptainer-sle15_7
elemental-support
elemental-register
buildah-debugsource
buildah-debuginfo
buildah
buildah-tests
elemental-toolkit
docker-stable-debuginfo
docker-stable
docker-stable-bash-completion
docker-stable-rootless-extras
docker-stable-zsh-completion
docker-stable-fish-completion
docker
docker-debuginfo
docker-bash-completion
docker-fish-completion
docker-zsh-completion
docker-rootless-extras
google-guest-agent (Ubuntu package)
How to mitigate CVE-2025-58181
Fusion Content-Aware Storage - update to 1.1.0
watsonx Orchestrate Developer Edition - update to 2.3.0
watsonx.data - update to 2.3.1
IBM Cloud Pak System - update to 2.3.5.1
IBM Fusion HCI - update to 2.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 2
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
Storage Protect Server - update to 8.2.1
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.18, 9.0.15, 9.1.5
Splunk Enterprise - addressed in versions 9.3.10, 9.4.9, 10.0.4, 10.2.1
squashfuse-tools - update to 0.5.0-150600.3.2.1
libsquashfuse0 - update to 0.5.0-150600.3.2.1
squashfuse-debugsource - update to 0.5.0-150600.3.2.1
libsquashfuse0-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse - update to 0.5.0-150600.3.2.1
squashfuse-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-tools-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-devel - update to 0.5.0-150600.3.2.1
docker-buildx - addressed in versions 0.29.0-150000.241.2, 0.33.0-150000.250.1
docker-buildx-debuginfo - update to 0.29.0-150000.241.2
apptainer - update to 1.4.5-150600.4.12.1
apptainer-debuginfo - update to 1.4.5-150600.4.12.1
apptainer-sle16 - update to 1.4.5-150600.4.12.1
apptainer-sle15_6 - update to 1.4.5-150600.4.12.1
apptainer-leap - update to 1.4.5-150600.4.12.1
apptainer-sle15_7 - update to 1.4.5-150600.4.12.1
elemental-support - update to 1.8.1-160000.1.1
elemental-register - update to 1.8.1-160000.1.1
buildah-debugsource - addressed in versions 1.26.1-13, 1.34.1-15
buildah-debuginfo - addressed in versions 1.26.1-13, 1.34.1-15
buildah - addressed in versions 1.26.1-13, 1.34.1-15
buildah-tests - update to 1.34.1-15
elemental-toolkit - update to 2.3.2-160000.1.1
Splunk Operator for Kubernetes Add-on - update to 3.1.0
docker-stable-debuginfo - addressed in versions 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.39.1
docker-stable - addressed in versions 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.39.1
docker-stable-bash-completion - addressed in versions 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.39.1
docker-stable-rootless-extras - update to 24.0.9_ce-150000.1.39.1
docker-stable-zsh-completion - update to 24.0.9_ce-150000.1.39.1
docker-stable-fish-completion - update to 24.0.9_ce-150000.1.39.1
docker - addressed in versions 28.5.1_ce-98.151.1, 28.5.1_ce-150000.241.2, 29.4.0_ce-150000.250.1
docker-debuginfo - addressed in versions 28.5.1_ce-98.151.1, 28.5.1_ce-150000.241.2, 29.4.0_ce-150000.250.1
docker-bash-completion - addressed in versions 28.5.1_ce-98.151.1, 28.5.1_ce-150000.241.2, 29.4.0_ce-150000.250.1
docker-fish-completion - update to 28.5.1_ce-150000.241.2
docker-zsh-completion - addressed in versions 28.5.1_ce-150000.241.2, 29.4.0_ce-150000.250.1
docker-rootless-extras - addressed in versions 28.5.1_ce-150000.241.2, 29.4.0_ce-150000.250.1
google-guest-agent (Ubuntu package) - addressed in versions 20240716.00-0ubuntu1~16.04.0+esm2, 20241011.01-0ubuntu1~18.04.0+esm2, 20250116.00-0ubuntu1~20.04.0+esm2, 20250116.00-0ubuntu1~22.04.2, 20250116.00-0ubuntu1~24.04.3, 20250116.00-0ubuntu2.2, 20250506.01-0ubuntu1.1
External References
Related Security Bulletins
- Denial of service in Go crypto ssh agent
- Multiple vulnerabilities in Splunk Enterprise
- SUSE update for apptainer
- SUSE update for docker
- SUSE update for docker
- Ubuntu update for google-guest-agent
- SUSE update for elemental-register, elemental-toolkit
- SUSE update for docker-stable
- Multiple vulnerabilities in IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in IBM Maximo Application Suite - Visual Inspection Component
- Multiple vulnerabilities in IBM watsonx Orchestrate Developer Edition
- Multiple vulnerabilities in IBM Storage Protect Server
- SUSE update for docker-stable
- IBM Watson Speech Services Cartridge update for Golang Go
- Splunk Operator for Kubernetes Add-on update for third-party components
- Multiple vulnerabilities in Communications Unified Assurance
- SUSE update for docker
- Multiple vulnerabilities in IBM Cloud Pak System
- openEuler 24.03 LTS SP4 update for buildah
- openEuler 24.03 LTS SP3 update for buildah
- openEuler 24.03 LTS SP1 update for buildah
- openEuler 22.03 LTS SP4 update for buildah
- Multiple vulnerabilities in IBM Fusion, IBM Fusion HCI, and IBM Fusion Content-Aware Storage