| Name | CVE-2025-22874 |
| Description | Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1107364 |
Vulnerable and fixed packages
The table below lists information on source packages.
The information below is based on the following data on fixed versions.
Notes
- golang-1.23 <not-affected> (Vulnerable code not present)
- golang-1.19 <not-affected> (Vulnerable code not present)
- golang-1.15 <not-affected> (Vulnerable code not present)
https://github.com/golang/go/issues/73612
Fixed by: https://github.com/golang/go/commit/03811ab1b31525e8d779997db169c6fedab7c505 (go1.24.4)
Introduced with: https://github.com/golang/go/commit/e8d95619978c4602d4446f113b3b69b7a22308fa (go1.24rc1)