First published: Mon May 05 2025(Updated: )
In Buoyant Edge releases before edge-25.2.1 and Enterprise for Linkerd releases 2.16.* before 2.16.5, 2.17.* before 2.17.2, and 2.18.* before 2.18.0, resource exhaustion can occur for Linkerd proxy metrics.
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/linkerd/linkerd2 | <0.6.0-20250501173313-4823b7af3e1e | 0.6.0-20250501173313-4823b7af3e1e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of GHSA-42mr-jpwh-m9rv is classified as high due to potential resource exhaustion in Linkerd proxy metrics.
To fix GHSA-42mr-jpwh-m9rv, upgrade to Buoyant Edge version edge-25.2.1 or Linkerd versions 2.16.5, 2.17.2, or 2.18.0 or later.
Symptoms of GHSA-42mr-jpwh-m9rv may include degraded performance or unresponsive services due to resource exhaustion.
GHSA-42mr-jpwh-m9rv affects Buoyant Edge releases prior to edge-25.2.1 and Linkerd versions 2.16.* before 2.16.5, 2.17.* before 2.17.2, and 2.18.* before 2.18.0.
Organizations using affected versions of Buoyant Edge or Linkerd should be concerned about GHSA-42mr-jpwh-m9rv and take immediate action to remediate.