CVE-2025-25199

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 12, 2025
CWE ID 401

Summary

CVE-2025-25199 is a memory leak vulnerability affecting the go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41, the `cng.TLS1PRF` function failed to release key handles, resulting in a small memory leak each time it was called. The issue has since been addressed in commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41 and is fixed in versions 1.23.6-2 and 1.22.12-2 of the Microsoft build of go, as well as in pseudoversion 0.0.0-20250211154640-f49c8e1379ea of the `github.com/microsoft/go-crypto-winnative` Go package.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share