vulnerability

Amazon Linux 2023: CVE-2025-58189: Important priority package update for golang (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Oct 29, 2025
Added
Oct 31, 2025
Modified
Dec 4, 2025

Description

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Solutions

amazon-linux-2023-upgrade-amazon-cloudwatch-agentamazon-linux-2023-upgrade-containerdamazon-linux-2023-upgrade-containerd-debuginfoamazon-linux-2023-upgrade-containerd-debugsourceamazon-linux-2023-upgrade-containerd-stressamazon-linux-2023-upgrade-containerd-stress-debuginfoamazon-linux-2023-upgrade-dockeramazon-linux-2023-upgrade-docker-debuginfoamazon-linux-2023-upgrade-docker-debugsourceamazon-linux-2023-upgrade-golangamazon-linux-2023-upgrade-golang-binamazon-linux-2023-upgrade-golang-docsamazon-linux-2023-upgrade-golang-miscamazon-linux-2023-upgrade-golang-sharedamazon-linux-2023-upgrade-golang-srcamazon-linux-2023-upgrade-golang-testsamazon-linux-2023-upgrade-golistamazon-linux-2023-upgrade-golist-debuginfoamazon-linux-2023-upgrade-golist-debugsourceamazon-linux-2023-upgrade-nerdctlamazon-linux-2023-upgrade-oci-add-hooksamazon-linux-2023-upgrade-oci-add-hooks-debuginfoamazon-linux-2023-upgrade-oci-add-hooks-debugsourceamazon-linux-2023-upgrade-runcamazon-linux-2023-upgrade-runc-debuginfoamazon-linux-2023-upgrade-runc-debugsourceamazon-linux-2023-upgrade-soci-snapshotter
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.