RHSA-2025:3959: Important: VolSync 0.11.2 security fixes and enhancements for RHEL 9
Important: VolSync 0.11.2 security fixes and enhancements for RHEL 9
Other sources
VolSync v0.11.2 is a Kubernetes operator that enables asynchronous replication<br>of persistent volumes within a cluster, or across clusters. After deploying<br>the VolSync operator, it can create and maintain copies of your persistent<br>data.<br>For more information about VolSync, see:<br><a href="https://docs.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.10/html/businesscontinuity/business-cont-overview#volsync" target="blank">https://docs.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.10/html/businesscontinuity/business-cont-overview#volsync</a> or the VolSync open source community website at:<br><a href="https://volsync.readthedocs.io/en/stable/" target="blank">https://volsync.readthedocs.io/en/stable/</a> This advisory contains enhancements and updates to the VolSync<br>container images.<br>Security fix(es):<br><li> golang.org/x/oauth2: Unexpected memory consumption during token parsing in</li> golang.org/x/oauth2 (CVE-2025-22868)<br><li> golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of</li> golang.org/x/crypto/ssh (CVE-2025-22869)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:3959?
RHSA-2025:3959 is classified as important due to security fixes and enhancements in VolSync 0.11.2.
How do I fix RHSA-2025:3959?
To fix RHSA-2025:3959, you need to update to VolSync version 0.11.2 or later in your Red Hat Advanced Cluster Management for Kubernetes deployment.
What are the main features of VolSync 0.11.2 relevant to RHSA-2025:3959?
VolSync 0.11.2 provides enhancements for asynchronous replication of persistent volumes within Kubernetes clusters.
Who is affected by RHSA-2025:3959?
RHSA-2025:3959 affects users of Red Hat Advanced Cluster Management for Kubernetes utilizing VolSync.
What should I do if I can't update to fix RHSA-2025:3959?
If unable to update for RHSA-2025:3959, consider implementing additional security measures and monitoring your environment closely.