RHSA-2025:3959: Important: VolSync 0.11.2 security fixes and enhancements for RHEL 9

Published Apr 16, 2025
·
Updated

Important: VolSync 0.11.2 security fixes and enhancements for RHEL 9

Other sources

VolSync v0.11.2 is a Kubernetes operator that enables asynchronous replication<br>of persistent volumes within a cluster, or across clusters. After deploying<br>the VolSync operator, it can create and maintain copies of your persistent<br>data.<br>For more information about VolSync, see:<br><a href="https://docs.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.10/html/businesscontinuity/business-cont-overview#volsync" target="blank">https://docs.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.10/html/businesscontinuity/business-cont-overview#volsync</a> or the VolSync open source community website at:<br><a href="https://volsync.readthedocs.io/en/stable/" target="blank">https://volsync.readthedocs.io/en/stable/</a> This advisory contains enhancements and updates to the VolSync<br>container images.<br>Security fix(es):<br><li> golang.org/x/oauth2: Unexpected memory consumption during token parsing in</li> golang.org/x/oauth2 (CVE-2025-22868)<br><li> golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of</li> golang.org/x/crypto/ssh (CVE-2025-22869)

Red Hat

Affected Software

1 affected component
Red Hat Red Hat Advanced Cluster Management for Kubernetes

Remediation

Event History

Apr 16, 2025
Advisory Published
via Red Hat·06:08 PM
May 6, 2025
Advisory Published
via Red Hat·06:46 PM
Data Sourced
via Red Hat·06:46 PM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2025:3959?

RHSA-2025:3959 is classified as important due to security fixes and enhancements in VolSync 0.11.2.

2

How do I fix RHSA-2025:3959?

To fix RHSA-2025:3959, you need to update to VolSync version 0.11.2 or later in your Red Hat Advanced Cluster Management for Kubernetes deployment.

3

What are the main features of VolSync 0.11.2 relevant to RHSA-2025:3959?

VolSync 0.11.2 provides enhancements for asynchronous replication of persistent volumes within Kubernetes clusters.

4

Who is affected by RHSA-2025:3959?

RHSA-2025:3959 affects users of Red Hat Advanced Cluster Management for Kubernetes utilizing VolSync.

5

What should I do if I can't update to fix RHSA-2025:3959?

If unable to update for RHSA-2025:3959, consider implementing additional security measures and monitoring your environment closely.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203