CVE-2025-61729

Publication date 2 December 2025

Last updated 3 December 2025


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

Description

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.

Status

Package Ubuntu Release Status
golang-1.24 25.10 questing
Needs evaluation
25.04 plucky
Needs evaluation
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
golang-1.25 25.10 questing
Needs evaluation
25.04 plucky Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release

Severity score breakdown

Parameter Value
Base score 7.5 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H