CVE-2025-58185: Parsing DER payload can cause memory exhaustion in encoding/asn1
Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
Other sources
Parsing DER payload can cause memory exhaustion in encoding/asn1
— Microsoft
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58185?
CVE-2025-58185 is a severe vulnerability that can cause memory exhaustion due to the parsing of malformed DER payloads.
How do I fix CVE-2025-58185?
To fix CVE-2025-58185, update to the latest versions of the affected Microsoft products as they contain necessary patches.
What products are affected by CVE-2025-58185?
CVE-2025-58185 affects several Microsoft products including azl3 golang versions 1.25.3-1 and 1.23.12-1, as well as cbl2 golang and gcc packages.
What are the potential impacts of CVE-2025-58185?
The potential impacts of CVE-2025-58185 include system instability and denial of service due to excessive memory allocation.
How can I identify if my system is vulnerable to CVE-2025-58185?
You can identify if your system is vulnerable to CVE-2025-58185 by checking the version of the installed Microsoft software against the list of affected versions.