Red Hat issued Important security updates for VolSync, Gatekeeper, and Multicluster Global Hub to remediate CVE-2025-22869, a high-severity denial-of-service vulnerability in golang.org/x/crypto/ssh. A malicious SSH client can deliberately stall or never finish key exchange, causing affected servers that implement file-transfer protocols to retain pending content in memory. The flaw is fixed in golang.org/x/crypto version v0.35.0 and later.
The advisories also remediate CVE-2025-22868, which can trigger unexpected memory consumption while golang.org/x/oauth2/jws parses tokens. Affected organizations should apply the relevant Red Hat errata and updated container images across supported architectures; Red Hat also instructed customers to install prerequisite errata before deploying the Multicluster Global Hub update. OpenShift Container Platform 4.15.55 separately addressed CVE-2025-22868 through its normal release channels.

See affected versions and whether adversaries are exploiting it.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:7391 for Podman on RHEL 9, providing podman-5.4.0-9.el9_6 packages for x86_64, s390x, ppc64le, and aarch64. The update remediates CVE-2025-22869 in golang.org/x/crypto/ssh and CVE-2025-27144 in go-jose.
Red Hat issued RHSA-2025:7462 for Podman on RHEL 10, providing podman-5.4.0-9.el10_0 packages that remediate CVE-2025-22869 in golang.org/x/crypto/ssh and CVE-2025-27144 in go-jose. The update was supplied for x86_64, aarch64, ppc64le, and s390x systems.
Red Hat issued RHSA-2025:4502 for Advanced Cluster Management for Kubernetes 2.10.8 on RHEL 9, providing updated container images for aarch64, ppc64le, s390x, and x86_64. The update remediates CVE-2025-22869 in golang.org/x/crypto/ssh and CVE-2025-30204 in golang-jwt/jwt.
Red Hat issued RHSA-2025:4002 for Red Hat Advanced Cluster Management for Kubernetes 2.12.3 on RHEL 9. The updated container images remediate CVE-2025-22869 in golang.org/x/crypto/ssh and CVE-2025-22868 in golang.org/x/oauth2/jws.
Red Hat issued RHSA-2025:3959 for VolSync 0.11.2 container images used with Advanced Cluster Management for Kubernetes 2 on RHEL 9. The update remediates CVE-2025-22869 in golang.org/x/crypto/ssh and CVE-2025-22868 in golang.org/x/oauth2/jws, with updated images for aarch64, ppc64le, s390x, and x86_64.
Red Hat issued RHSA-2025:3932 for OpenShift Dev Spaces 3.20.0, updating x86_64 Dev Spaces containers and remediating CVE-2025-22869 in golang.org/x/crypto/ssh. The advisory also fixes CVE-2025-22868 in golang.org/x/oauth2/jws and CVE-2024-12905 in tar-fs.
Red Hat issued RHSA-2025:3863 for the Multicluster Global Hub 1.3.3 general-availability release, providing refreshed container images and fixes for CVE-2025-22869 in golang.org/x/crypto/ssh and CVE-2025-22868 in golang.org/x/oauth2/jws. Updated images were supplied for aarch64, ppc64le, s390x, and x86_64 architectures.
RHSA-2025:3498 released updated Red Hat Multicluster Global Hub 1.2.2 container images and remediated CVE-2025-22869 in golang.org/x/crypto/ssh, alongside CVE-2025-22868.
RHSA-2025:3172 released VolSync 0.12.1 container images for Red Hat Advanced Cluster Management for Kubernetes 2 on RHEL 9. The update fixes CVE-2025-22869 and CVE-2025-22868.
Red Hat issued RHSA-2025:3051 for Gatekeeper 3.17.2, remediating CVE-2025-22869 and CVE-2025-22868 and providing updated container images for multiple architectures.
Red Hat issued RHSA-2025:3053 for Gatekeeper 3.15.4, addressing CVE-2025-22869 in SSH key exchange as well as CVE-2025-22868 in golang.org/x/oauth2/jws.
Red Hat's Bugzilla record 2348367 for CVE-2025-22869 was reported. The high-severity flaw allows an SSH client to delay or abandon key exchange, causing affected file-transfer SSH servers to retain pending content in memory.
Red Hat released OpenShift Container Platform 4.15.51 as an Important security and bug-fix update for OpenShift 4.15. The update provides refreshed container images and remediates CVE-2025-22869 in golang.org/x/crypto/ssh across supported RHEL 8 and RHEL 9 architectures.
The denial-of-service vulnerability in golang.org/x/crypto/ssh was fixed in golang.org/x/crypto version 0.35.0 and later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.