Release Date: | 2025-04-08 | |
Impact: | Moderate | What is this? |
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
See more information about CVE-2025-22871 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS metrics and score provided are preliminary and subject to review.
Base Score: | 5.4 |
Vector String: | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N |
Version: | 3.1 |
Attack Vector: | Network |
Attack Complexity: | High |
Privileges Required: | None |
User Interaction: | None |
Scope: | Changed |
Confidentiality Impact: | Low |
Integrity Impact: | Low |
Availability Impact: | None |
Platform | Errata | Release Date |
Oracle Linux version 10 (buildah) | ELSA-2025-9148 | 2025-06-27 |
Oracle Linux version 10 (delve) | ELSA-2025-9317 | 2025-06-27 |
Oracle Linux version 10 (git-lfs) | ELSA-2025-9063 | 2025-06-26 |
Oracle Linux version 10 (golang) | ELSA-2025-8477 | 2025-06-27 |
Oracle Linux version 10 (golang-github-openprinting-ipp-usb) | ELSA-2025-9156 | 2025-06-27 |
Oracle Linux version 10 (grafana) | ELSA-2025-8666 | 2025-06-30 |
Oracle Linux version 10 (grafana-pcp) | ELSA-2025-8915 | 2025-06-27 |
Oracle Linux version 10 (gvisor-tap-vsock) | ELSA-2025-9151 | 2025-06-27 |
Oracle Linux version 10 (osbuild-composer) | ELSA-2025-9623 | 2025-07-01 |
Oracle Linux version 10 (podman) | ELSA-2025-9146 | 2025-06-27 |
Oracle Linux version 10 (skopeo) | ELSA-2025-9149 | 2025-06-30 |
Oracle Linux version 8 (aardvark-dns) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (buildah) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (cockpit-podman) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (conmon) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (container-selinux) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (containernetworking-plugins) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (containers-common) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (criu) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (crun) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (delve) | ELSA-2025-8478 | 2025-06-04 |
Oracle Linux version 8 (fuse-overlayfs) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (git-lfs) | ELSA-2025-9060 | 2025-06-16 |
Oracle Linux version 8 (go-toolset) | ELSA-2025-8478 | 2025-06-04 |
Oracle Linux version 8 (golang) | ELSA-2025-8478 | 2025-06-04 |
Oracle Linux version 8 (grafana) | ELSA-2025-8667 | 2025-06-09 |
Oracle Linux version 8 (grafana-pcp) | ELSA-2025-8918 | 2025-06-11 |
Oracle Linux version 8 (libslirp) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (netavark) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (oci-seccomp-bpf-hook) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (osbuild-composer) | ELSA-2025-9844 | 2025-06-27 |
Oracle Linux version 8 (podman) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (python-podman) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (runc) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (skopeo) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (slirp4netns) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (udica) | ELSA-2025-9142 | 2025-06-17 |
Oracle Linux version 8 (weldr-client) | ELSA-2025-9845 | 2025-06-26 |
Oracle Linux version 9 (buildah) | ELSA-2025-9147 | 2025-06-17 |
Oracle Linux version 9 (containernetworking-plugins) | ELSA-2025-9143 | 2025-06-16 |
Oracle Linux version 9 (git-lfs) | ELSA-2025-9106 | 2025-06-16 |
Oracle Linux version 9 (golang) | ELSA-2025-8476 | 2025-06-04 |
Oracle Linux version 9 (grafana) | ELSA-2025-8682 | 2025-06-09 |
Oracle Linux version 9 (grafana-pcp) | ELSA-2025-8916 | 2025-06-11 |
Oracle Linux version 9 (gvisor-tap-vsock) | ELSA-2025-9150 | 2025-06-16 |
Oracle Linux version 9 (osbuild-composer) | ELSA-2025-9634 | 2025-06-25 |
Oracle Linux version 9 (podman) | ELSA-2025-9144 | 2025-06-17 |
Oracle Linux version 9 (skopeo) | ELSA-2025-9145 | 2025-06-16 |
Oracle Linux version 9 (weldr-client) | ELSA-2025-9635 | 2025-06-25 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections: