First published: Tue Mar 25 2025(Updated: )
A replacement for libslirp and VPNKit, written in pure Go. It is based on the network stack of gVisor and is used to provide networking for podman-machine virtual machines. Compared to libslirp, gvisor-tap-vsock brings a configurable DNS server and dynamic port forwarding.<br>Security Fix(es):<br><li> golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (CVE-2025-22869)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gvisor-tap-vsock | <0.7.3-5.el9_4.1 | 0.7.3-5.el9_4.1 |
redhat/gvisor-tap-vsock | <0.7.3-5.el9_4.1 | 0.7.3-5.el9_4.1 |
redhat/gvisor-tap-vsock-debuginfo | <0.7.3-5.el9_4.1 | 0.7.3-5.el9_4.1 |
redhat/gvisor-tap-vsock-debugsource | <0.7.3-5.el9_4.1 | 0.7.3-5.el9_4.1 |
redhat/gvisor-tap-vsock-debuginfo | <0.7.3-5.el9_4.1 | 0.7.3-5.el9_4.1 |
redhat/gvisor-tap-vsock-debugsource | <0.7.3-5.el9_4.1 | 0.7.3-5.el9_4.1 |
redhat/gvisor-tap-vsock | <0.7.3-5.el9_4.1 | 0.7.3-5.el9_4.1 |
redhat/gvisor-tap-vsock-debuginfo | <0.7.3-5.el9_4.1 | 0.7.3-5.el9_4.1 |
redhat/gvisor-tap-vsock-debugsource | <0.7.3-5.el9_4.1 | 0.7.3-5.el9_4.1 |
redhat/gvisor-tap-vsock | <0.7.3-5.el9_4.1.aa | 0.7.3-5.el9_4.1.aa |
redhat/gvisor-tap-vsock-debuginfo | <0.7.3-5.el9_4.1.aa | 0.7.3-5.el9_4.1.aa |
redhat/gvisor-tap-vsock-debugsource | <0.7.3-5.el9_4.1.aa | 0.7.3-5.el9_4.1.aa |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions | ||
Red Hat Enterprise Linux for x86_64 - Extended Update Support | ||
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | ||
Red Hat Enterprise Linux for IBM z Systems | ||
Red Hat Enterprise Linux for ARM 64 | ||
Red Hat Enterprise Linux Server for IBM z Systems | ||
Red Hat Enterprise Linux Server | ||
Red Hat Enterprise Linux for SAP Solutions | ||
Red Hat Enterprise Linux for ARM64 EUS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2025:3185 is classified as important.
You can fix RHSA-2025:3185 by updating to the fixed version 0.7.3-5.el9_4.1 for gvisor-tap-vsock.
Affected packages include gvisor-tap-vsock, gvisor-tap-vsock-debuginfo, and gvisor-tap-vsock-debugsource among others.
More information about RHSA-2025:3185 can be found in the Red Hat security advisory.
The impacted versions for RHSA-2025:3185 include versions prior to 0.7.3-5.el9_4.1.