vulnerability
Amazon Linux 2023: CVE-2025-58189: Important priority package update for golang (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:P/A:N) | Oct 29, 2025 | Oct 31, 2025 | Dec 4, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Oct 29, 2025
Added
Oct 31, 2025
Modified
Dec 4, 2025
Description
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
Solutions
amazon-linux-2023-upgrade-amazon-cloudwatch-agentamazon-linux-2023-upgrade-containerdamazon-linux-2023-upgrade-containerd-debuginfoamazon-linux-2023-upgrade-containerd-debugsourceamazon-linux-2023-upgrade-containerd-stressamazon-linux-2023-upgrade-containerd-stress-debuginfoamazon-linux-2023-upgrade-dockeramazon-linux-2023-upgrade-docker-debuginfoamazon-linux-2023-upgrade-docker-debugsourceamazon-linux-2023-upgrade-golangamazon-linux-2023-upgrade-golang-binamazon-linux-2023-upgrade-golang-docsamazon-linux-2023-upgrade-golang-miscamazon-linux-2023-upgrade-golang-sharedamazon-linux-2023-upgrade-golang-srcamazon-linux-2023-upgrade-golang-testsamazon-linux-2023-upgrade-golistamazon-linux-2023-upgrade-golist-debuginfoamazon-linux-2023-upgrade-golist-debugsourceamazon-linux-2023-upgrade-nerdctlamazon-linux-2023-upgrade-oci-add-hooksamazon-linux-2023-upgrade-oci-add-hooks-debuginfoamazon-linux-2023-upgrade-oci-add-hooks-debugsourceamazon-linux-2023-upgrade-runcamazon-linux-2023-upgrade-runc-debuginfoamazon-linux-2023-upgrade-runc-debugsourceamazon-linux-2023-upgrade-soci-snapshotter
References
- CVE-2025-58189
- https://attackerkb.com/topics/CVE-2025-58189
- URL-https://alas.aws.amazon.com/AL2023/ALAS-2025-1239.html
- URL-https://alas.aws.amazon.com/AL2023/ALAS-2025-1272.html
- URL-https://alas.aws.amazon.com/AL2023/ALAS-2025-1273.html
- URL-https://alas.aws.amazon.com/AL2023/ALAS-2025-1274.html
- URL-https://alas.aws.amazon.com/AL2023/ALAS-2025-1275.html
- URL-https://alas.aws.amazon.com/AL2023/ALAS-2025-1276.html
- URL-https://alas.aws.amazon.com/AL2023/ALAS-2025-1277.html
- URL-https://alas.aws.amazon.com/AL2023/ALAS-2025-1278.html
- URL-https://alas.aws.amazon.com/AL2023/ALAS-2025-1286.html
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.