First published: Tue May 13 2025(Updated: )
A replacement for libslirp and VPNKit, written in pure Go. It is based on the network stack of gVisor. Compared to libslirp, gvisor-tap-vsock brings a configurable DNS server and dynamic port forwarding.<br>Security Fix(es):<br><li> golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (CVE-2025-22869)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux 8 | ||
Red Hat Enterprise Linux Server for IBM z Systems | ||
Red Hat Enterprise Linux for ARM 64 | ||
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | ||
redhat/gvisor-tap-vsock | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-debuginfo | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-debugsource | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-gvforwarder | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-gvforwarder-debuginfo | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-debuginfo | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-debugsource | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-gvforwarder | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-gvforwarder-debuginfo | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-debuginfo | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-debugsource | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-gvforwarder | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock-gvforwarder-debuginfo | <0.8.5-1.el9_6 | 0.8.5-1.el9_6 |
redhat/gvisor-tap-vsock | <0.8.5-1.el9_6.aa | 0.8.5-1.el9_6.aa |
redhat/gvisor-tap-vsock-debuginfo | <0.8.5-1.el9_6.aa | 0.8.5-1.el9_6.aa |
redhat/gvisor-tap-vsock-debugsource | <0.8.5-1.el9_6.aa | 0.8.5-1.el9_6.aa |
redhat/gvisor-tap-vsock-gvforwarder | <0.8.5-1.el9_6.aa | 0.8.5-1.el9_6.aa |
redhat/gvisor-tap-vsock-gvforwarder-debuginfo | <0.8.5-1.el9_6.aa | 0.8.5-1.el9_6.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2025:7416 is classified as important.
To fix RHSA-2025:7416, you need to update the gvisor-tap-vsock package to version 0.8.5-1.el9_6.
RHSA-2025:7416 affects various versions of Red Hat Enterprise Linux including x86_64, IBM z Systems, ARM 64, and Power, little endian.
RHSA-2025:7416 addresses a denial of service vulnerability in the golang.org/x/crypto/ssh package.
Yes, gvisor-tap-vsock includes support for dynamic port forwarding.