CVE-2025-47914Patch(golang / crypto)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang crypto systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crypto

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
crypto

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-16: 1Patch / Workaround · 2026-06-16: 1Technical Details · 2026-06-16: 106-16
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatCluster@threatcluster
    Patch

    SUSE released fixes for kubevirt 1.6 and 1.7 addressing CVE-2025-47911, CVE-2025-47913 and CVE-2025-47914 privilege escalation and denial-of-service bugs in embedded Go components, Linuxsecurity reported. https://threatcluster.io/cluster/critical-vulnerabilities-in-suse-kubevirt-and-opensuse-trivy-ce749196

    Post summary

    The announcement announces that SUSE has released patches for kubevirt versions 1.6 and 1.7 to fix privilege escalation and denial‑of‑service CVEs in embedded Go components.

    0000061
    349 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolangcrypto-go-

Explore more