CVE Vulnerabilities

CVE-2025-22865

Published: Jan 28, 2025 | Modified: Jan 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Ceph Storage 7.1RedHatrhceph/grafana-rhel10:11.6.2-7*
Red Hat Ceph Storage 7.1RedHatrhceph/grafana-rhel9:11.6.2-7*
Red Hat Ceph Storage 7.1RedHatrhceph/keepalived-rhel9:2.2.8-74*
Red Hat Ceph Storage 7.1RedHatrhceph/rhceph-7-rhel9:7-532*
Red Hat Ceph Storage 7.1RedHatrhceph/rhceph-haproxy-rhel9:2.4.22-76*
Red Hat Ceph Storage 7.1RedHatrhceph/rhceph-promtail-rhel9:v3.0.0-41*
Red Hat Ceph Storage 7.1RedHatrhceph/snmp-notifier-rhel9:1.2.1-124*
Red Hat Ceph Storage 8.1RedHatrhceph/grafana-rhel9:11.6.2-4*
Golang-1.13Ubuntufocal*
Golang-1.14Ubuntufocal*
Golang-1.16Ubuntufocal*
Golang-1.18Ubuntufocal*
Golang-1.20Ubuntufocal*
Golang-1.21Ubuntufocal*
Golang-1.22Ubuntufocal*
Golang-1.23Ubuntuoracular*
Golang-1.23Ubuntuplucky*
Golang-1.24Ubuntuplucky*

References