vulnerability

Amazon Linux 2023: CVE-2025-58189: Important priority package update for golang (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Oct 29, 2025
Added
Oct 31, 2025
Modified
Nov 11, 2025

Description

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Solutions

amazon-linux-2023-upgrade-amazon-cloudwatch-agentamazon-linux-2023-upgrade-containerdamazon-linux-2023-upgrade-containerd-debuginfoamazon-linux-2023-upgrade-containerd-debugsourceamazon-linux-2023-upgrade-containerd-stressamazon-linux-2023-upgrade-containerd-stress-debuginfoamazon-linux-2023-upgrade-dockeramazon-linux-2023-upgrade-docker-debuginfoamazon-linux-2023-upgrade-docker-debugsourceamazon-linux-2023-upgrade-golangamazon-linux-2023-upgrade-golang-binamazon-linux-2023-upgrade-golang-docsamazon-linux-2023-upgrade-golang-miscamazon-linux-2023-upgrade-golang-sharedamazon-linux-2023-upgrade-golang-srcamazon-linux-2023-upgrade-golang-testsamazon-linux-2023-upgrade-golistamazon-linux-2023-upgrade-golist-debuginfoamazon-linux-2023-upgrade-golist-debugsourceamazon-linux-2023-upgrade-nerdctlamazon-linux-2023-upgrade-oci-add-hooksamazon-linux-2023-upgrade-oci-add-hooks-debuginfoamazon-linux-2023-upgrade-oci-add-hooks-debugsourceamazon-linux-2023-upgrade-runcamazon-linux-2023-upgrade-runc-debuginfoamazon-linux-2023-upgrade-runc-debugsourceamazon-linux-2023-upgrade-soci-snapshotter

References

    Title
    NEW

    Explore Exposure Command

    Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.