VDB
RHSA-2025%3A19381
RHSA-2025%3A19381
PUBLISHED
CVSS 7 HIGH
A flaw was found in database/sql. Concurrent queries can produce unexpected results when a query is cancelled during a Scan method call on returned Rows, creating a race condition. This vulnerability allows an attacker who can initiate and cancel queries to trigger this condition, possibly leading to inconsistent data being returned to the application.
Risk Scores
CVSS 3.1
7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:6083afd8a79e3a0db09004e90d8084d237db97369940c1e9725dd03729e0d734_amd64 as a component of multicluster engine for Kubernetes 2.9 | registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:6083afd8a79e3a0db09004e90d8084d237db97369940c1e9725dd03729e0d734_amd64 |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:681e182f48d1cd275d7c097f004d3f5eb305ebb8dd62f0bb07b1a63f9ea87146_arm64 as a component of multicluster engine for Kubernetes 2.9 | registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:681e182f48d1cd275d7c097f004d3f5eb305ebb8dd62f0bb07b1a63f9ea87146_arm64 |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:7994a6075605f6788e3a69fd005d5fc6cbcdd34d86fed1e479e1a553b452a558_s390x as a component of multicluster engine for Kubernetes 2.9 | registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:7994a6075605f6788e3a69fd005d5fc6cbcdd34d86fed1e479e1a553b452a558_s390x |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:247d68d562a9d22e5d1eaa186f0e6d067a453655cfd1e6fa2b58e33b22771163_ppc64le as a component of multicluster engine for Kubernetes 2.9 | * |
Timeline
- Oct 30, 2025 CVE Published
- May 7, 2026 CVE Updated
- May 7, 2026 Distribution Patch
- May 7, 2026 Distribution Patch
- May 7, 2026 Security Advisory
- May 7, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:19381 advisory
- https://access.redhat.com/security/cve/CVE-2025-47907 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_19381.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2387083 issue
- https://www.cve.org/CVERecord?id=CVE-2025-47907 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-47907 advisory
- https://go.dev/cl/693735 advisory
- https://go.dev/issue/74831 advisory
- https://groups.google.com/g/golang-announce/c/x5MKroML2yM advisory
- https://pkg.go.dev/vuln/GO-2025-3849 advisory