--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2025-cf30052f95
2026-01-07 00:24:44.246572+00:00
--------------------------------------------------------------------------------

Name        : kustomize
Product     : Fedora EPEL 10.2
Version     : 5.8.0
Release     : 1.el10_2
URL         : https://github.com/kubernetes-sigs/kustomize
Summary     : Customization of kubernetes YAML configurations
Description :
Customization of kubernetes YAML configurations.

--------------------------------------------------------------------------------
Update Information:

Update to 5.8.0
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 29 2025 Mikel Olasagasti Uranga <[email protected]> - 5.8.0-1
- Update to 5.8.0 - Closes rhbz#2413654
* Fri Oct 10 2025 Maxwell G <[email protected]> - 5.7.1-3
- Rebuild for golang 1.25.2
* Fri Aug 15 2025 Maxwell G <[email protected]> - 5.7.1-2
- Rebuild for golang-1.25.0
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2390834 - kustomize: go-viper's mapstructure May Leak Sensitive 
Information in Logs [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2390834
  [ 2 ] Bug #2398301 - CVE-2025-47910 kustomize: CrossOriginProtection bypass 
in net/http [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2398301
  [ 3 ] Bug #2398937 - CVE-2025-47906 kustomize: Unexpected paths returned from 
LookPath in os/exec [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2398937
  [ 4 ] Bug #2399687 - CVE-2025-11065 kustomize: Go-viper's mapstructure May 
Leak Sensitive Information in Logs in github.com/go-viper/mapstructure [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2399687
  [ 5 ] Bug #2407486 - CVE-2025-58189 kustomize: go crypto/tls ALPN negotiation 
error contains attacker controlled information [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2407486
  [ 6 ] Bug #2408528 - CVE-2025-61725 kustomize: Excessive CPU consumption in 
ParseAddress in net/mail [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408528
  [ 7 ] Bug #2408938 - CVE-2025-61723 kustomize: Quadratic complexity when 
parsing some invalid inputs in encoding/pem [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408938
  [ 8 ] Bug #2409879 - CVE-2025-58185 kustomize: Parsing DER payload can cause 
memory exhaustion in encoding/asn1 [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2409879
  [ 9 ] Bug #2410820 - CVE-2025-58188 kustomize: Panic when validating 
certificates with DSA public keys in crypto/x509 [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2410820
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update kustomize' at the command line.
For more information, refer to "YUM", available at
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\
/html/System_Administrators_Guide/ch-yum.html

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
epel-package-announce mailing list -- 
[email protected]
To unsubscribe send an email to 
[email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to