Skip to content

Conversation

@spraveenio
Copy link
Contributor

Fix known vulnerabilities on the golang with version updated to 1.25.5

old gpuctl scan report

gpuctl (gobinary)

Total: 12 (UNKNOWN: 0, LOW: 0, MEDIUM: 8, HIGH: 4, CRITICAL: 0)                                                                                              
▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒
▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒
│ Library │ Vulnerability  │ Severity │ Status │ Installed Version │  Fixed Version  │                            Title                             │
▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒
▒ stdlib  ▒ CVE-2025-58183 ▒ HIGH     ▒ fixed  ▒ v1.24.6           ▒ 1.24.8, 1.25.2  ▒ golang: archive/tar: Unbounded allocation when parsing GNU   ▒
▒         ▒                ▒          ▒        ▒                   ▒                 ▒ sparse map                                                   ▒
▒         ▒                ▒          ▒        ▒                   ▒                 ▒ https://avd.aquasec.com/nvd/cve-2025-58183                   ▒
▒         ▒ CVE-2025-58186 ▒          ▒        ▒                   ▒                 ▒ Despite HTTP headers having a default limit of 1MB, the      ▒
▒         ▒                ▒          ▒        ▒                   ▒                 ▒ number of...                                                 ▒
▒         ▒                ▒          ▒        ▒                   ▒                 ▒ https://avd.aquasec.com/nvd/cve-2025-58186                   ▒
▒         ▒ CVE-2025-58187 ▒          ▒        ▒                   ▒ 1.24.9, 1.25.3  ▒ Due to the design of the name constraint checking algorithm, ▒
▒         ▒                ▒          ▒        ▒                   ▒                 ▒ the proce...                                                 ▒
▒         ▒                ▒          ▒        ▒                   ▒                 ▒ https://avd.aquasec.com/nvd/cve-2025-58187                   ▒
▒         ▒ CVE-2025-61729 ▒          ▒        ▒                   ▒ 1.24.11, 1.25.5 ▒ crypto/x509: Excessive resource consumption when printing    ▒
▒         ▒                ▒          ▒        ▒                   ▒                 ▒ error string for host certificate validation...              ▒
▒         ▒                ▒          ▒        ▒                   ▒                 ▒ https://avd.aquasec.com/nvd/cve-2025-61729                   ▒

@sarat-k sarat-k merged commit 8506ea7 into ROCm:main Dec 16, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants