Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage
🔗 CVE IDs covered (12)
📋 Description
CVE-2023-52355 — libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM CVE-2023-52356 — libtiff: Segment fault in libtiff in TIFFReadRGBATileExt() leading to denial of service CVE-2024-56433 — shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise CVE-2025-6965 — sqlite: Integer Truncation in SQLite CVE-2025-8176 — libtiff: LibTIFF Use-After-Free Vulnerability CVE-2025-8677 — bind: Resource exhaustion via malformed DNSKEY handling CVE-2025-9230 — openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap CVE-2025-9900 — libtiff: Libtiff Write-What-Where CVE-2025-40778 — bind: Cache poisoning attacks with unsolicited RRs CVE-2025-40780 — bind: Cache poisoning due to weak PRNG CVE-2025-53905 — vim: Vim path traversial CVE-2025-53906 — vim: Vim path traversal
🎯 Affected products5
- Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-server-rhel9@sha256:97a1bb076f7f29a5f2b80c4724cb27c4e87f89c2d73a7719c44dc8c044329503_amd64 as a component of Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-server-rhel9@sha256:b4683720677a1e45efbfd291d8b130b530642221e8a55a49e931e1b8b2c81ac3_arm64 as a component of Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-ui-rhel9@sha256:310df392f638ef6eca1a26db024ae2cb617db5932f886d2acddc92fb7289e740_arm64 as a component of Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-ui-rhel9@sha256:69cb9c84b806ee2f448bdbbcf3174855432f5caec8f31ca2a345655da4a72f57_amd64 as a component of Red Hat Discovery 2
✅ Remediation
The containers required to run Discovery can be installed through discovery-installer RPM. See the official documentation for more details. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. To reduce risk, restrict recursive queries to trusted or internal networks only, and apply rate limiting or firewall rules to prevent excessive or repetitive requests. Enabling DNSSEC validation helps reject forged records, while isolating recursive resolvers from authoritative servers limits the impact of potential cache poisoning. Active monitoring of CPU usage, query volume, and cache anomalies can provide early warning of abuse or attacks. Workaround: While it is not possible to eliminate risk from this vulnerability, there are several options for reducing the risk. These include restricting recursive queries to trusted or internal networks only, and apply rate limiting or firewall rules to prevent excessive or repetitive requests. Enabling DNSSEC validation helps reject forged records, while isolating recursive resolvers from authoritative servers limits the impact of potential cache poisoning. Active monitoring of CPU usage, query volume, and cache anomalies can provide early warning of abuse or attacks.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2025:21994
- externalhttps://access.redhat.com/security/cve/CVE-2023-52355
- externalhttps://access.redhat.com/security/cve/CVE-2023-52356
- externalhttps://access.redhat.com/security/cve/CVE-2024-56433
- externalhttps://access.redhat.com/security/cve/CVE-2025-40778
- externalhttps://access.redhat.com/security/cve/CVE-2025-40780
- externalhttps://access.redhat.com/security/cve/CVE-2025-53905
- externalhttps://access.redhat.com/security/cve/CVE-2025-53906
- externalhttps://access.redhat.com/security/cve/CVE-2025-6965
- externalhttps://access.redhat.com/security/cve/CVE-2025-8176
- externalhttps://access.redhat.com/security/cve/CVE-2025-8677
- externalhttps://access.redhat.com/security/cve/CVE-2025-9230
- externalhttps://access.redhat.com/security/cve/CVE-2025-9900
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/subscription_central/1-latest/#Discovery
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_21994.json