RHSA-2025:9151: Moderate: gvisor-tap-vsock security update
A replacement for libslirp and VPNKit, written in pure Go. It is based on the network stack of gVisor. Compared to libslirp, gvisor-tap-vsock brings a configurable DNS server and dynamic port forwarding.Security Fix(es): net/http: Request smuggling due to acceptance of invalid chunked data in net/http (CVE-2025-22871) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Moderate: gvisor-tap-vsock security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gvisor-tap-vsockto a version that resolves this vulnerability.Fixed in 0.8.5-2.el10_0 - Upgrade
Upgrade
redhat/gvisor-tap-vsock-debuginfoto a version that resolves this vulnerability.Fixed in 0.8.5-2.el10_0 - Upgrade
Upgrade
redhat/gvisor-tap-vsock-debugsourceto a version that resolves this vulnerability.Fixed in 0.8.5-2.el10_0 - Upgrade
Upgrade
redhat/gvisor-tap-vsock-gvforwarderto a version that resolves this vulnerability.Fixed in 0.8.5-2.el10_0 - Upgrade
Upgrade
redhat/gvisor-tap-vsock-gvforwarder-debuginfoto a version that resolves this vulnerability.Fixed in 0.8.5-2.el10_0 - Upgrade
Upgrade
redhat/gvisor-tap-vsockto a version that resolves this vulnerability.Fixed in 0.8.5-2.el10_0.aa - Upgrade
Upgrade
redhat/gvisor-tap-vsock-debuginfoto a version that resolves this vulnerability.Fixed in 0.8.5-2.el10_0.aa - Upgrade
Upgrade
redhat/gvisor-tap-vsock-debugsourceto a version that resolves this vulnerability.Fixed in 0.8.5-2.el10_0.aa - Upgrade
Upgrade
redhat/gvisor-tap-vsock-gvforwarderto a version that resolves this vulnerability.Fixed in 0.8.5-2.el10_0.aa - Upgrade
Upgrade
redhat/gvisor-tap-vsock-gvforwarder-debuginfoto a version that resolves this vulnerability.Fixed in 0.8.5-2.el10_0.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:9151?
The severity of RHSA-2025:9151 is classified as Moderate.
How do I fix RHSA-2025:9151?
To fix RHSA-2025:9151, update the gvisor-tap-vsock package to version 0.8.5-2.el10_0.
Which products are affected by RHSA-2025:9151?
RHSA-2025:9151 affects multiple versions of Red Hat Enterprise Linux for IBM z Systems, Power, and x86_64.
What is gvisor-tap-vsock in relation to RHSA-2025:9151?
gvisor-tap-vsock is a package associated with the security update in RHSA-2025:9151 that addresses vulnerabilities.
Are there any related packages to update for RHSA-2025:9151?
Yes, related packages include gvisor-tap-vsock-debuginfo, gvisor-tap-vsock-debugsource, and gvisor-tap-vsock-gvforwarder.