VDB

RHSA-2025:17043

RHSA-2025:17043 PUBLISHED CVSS 7.5 HIGH

A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/rhosdt/tempo-query-rhel8@sha256:44adfb0ca086be0d8b08586aa525416ea886adcda83acc1d68fe6a2cd37c16a1_arm64 as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-query-rhel8@sha256:78797b121dcdf1be79c6ba8824254c5e27ec18467e0872a493a675a373d8a9ef_s390x as a component of Red Hat OpenShift distributed tracing 3.7.1*
Red Hatregistry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:1d04cc80ad01b912e143f714702a604979ee83f4037b72663618637f0e77fd0b_s390x as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-rhel8@sha256:d8d259d3a1e47685bace6c824b3cc5fb1ac936d4a3ee607a3805797032d3af90_arm64 as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:4b1cce1957fa69b7f3f3cd86abf347e30aa5d53a1a308d4fe8f6b09f14d95aef_arm64 as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-query-rhel8@sha256:0cb8089183b98b3e0f88bf7889fe273bf7ce5aaf9be724841d5ec10f64850c27_amd64 as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:62b57fedbfb477fdee21ed6362d4dfdc16e542526eb18e5f3e59f1082f82fa0a_ppc64le as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:11e05573aa592a55b24338a9ed044b44dac8e6f7197f970845a122ac555ae104_ppc64le as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-operator-bundle@sha256:bcc3521d20a1662d4032901f46e3bd4744c9910b060f52bdf10c6a8dfea1276b_amd64 as a component of Red Hat OpenShift distributed tracing 3.7.1*
golangcrypto/x509
Red Hatregistry.redhat.io/rhosdt/tempo-query-rhel8@sha256:78797b121dcdf1be79c6ba8824254c5e27ec18467e0872a493a675a373d8a9ef_s390x as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:066beafc62aaaa24d851394da17a4e31b3590074ba10bccae65ad0ba51f66576_s390x as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-query-rhel8@sha256:06aceed4489f2775250050e9c0a97dbd0213eec023e25302d81cdcfd236406ef_ppc64le as a component of Red Hat OpenShift distributed tracing 3.7.1*
Red Hatregistry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:43057cca6db4491d95db1d865cdb2eff2caec367fd9ca58f6461f9952f733d84_amd64 as a component of Red Hat OpenShift distributed tracing 3.7.1*
Red Hatregistry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:3e3e58c2af0674641e4bc099c93413f8680ad82616ad3bc76b4c485aad8c778a_amd64 as a component of Red Hat OpenShift distributed tracing 3.7.1*
Red Hatregistry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:40922fdd421a4e9c1c14f1d05045d65e6d08d9dfbad372bcab97b637383f53d4_amd64 as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-rhel8@sha256:857b3bb9abb2b67c2fbde63d28651379c22b7e417a06f157c30d4c20b60004a8_amd64 as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-rhel8@sha256:956a4e80d64bb8a0e745c45ee260f3bc531d9006501f76f23ec4dc35d0282d07_ppc64le as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-rhel8@sha256:ed934b506edd780006adf9e279f0758f959c2fa326c5bf0eb4bcf47ac791a4e2_s390x as a component of Red Hat OpenShift distributed tracing 3.7.0*
Red Hatregistry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:40922fdd421a4e9c1c14f1d05045d65e6d08d9dfbad372bcab97b637383f53d4_amd64 as a component of Red Hat OpenShift distributed tracing 3.7.1*

…and 31 more

Timeline

  • Sep 30, 2025 CVE Published
  • May 16, 2026 Security Advisory
  • Aug 6, 2026 CVE Updated
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›