Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:14127 - Security Advisory
Issued:
2025-08-20
Updated:
2025-08-20

RHSA-2025:14127 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: pki-deps:10.6 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the pki-deps:10.6 module is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.

Security Fix(es):

  • com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError (CVE-2025-52999)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 8.2 x86_64

Fixes

  • BZ - 2374804 - CVE-2025-52999 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError

CVEs

  • CVE-2025-52999

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 8.2

SRPM
apache-commons-collections-3.2.2-10.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 8808d86cf51fbacb8385c8ab63619325a63a5b9c01d511b20f8116963d3ecd25
apache-commons-lang-2.6-21.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 8d21f5d5b04d5f6115278eb5610c074914188e978c7f3e4ba4efa9af9a90552a
bea-stax-1.2.0-16.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 6df5604c39f96f7bc1f72c2704d8af3e910773675f41751eeab3e92844c4f266
fasterxml-oss-parent-69-1.module+el8.2.0+23390+7631bd3f.src.rpm SHA-256: 87bca7aa5c045805d2bd91914068c421253f411898bd626dd856807527376515
glassfish-fastinfoset-1.2.13-9.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 54904a53c89d2e4c6b4500e3ccfbb15a21d01087d651f36f01c155ed88637934
glassfish-jaxb-2.2.11-11.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: fefd1ddbf106bf9e6c091f61a4215030c4db3c53068ef29f60f05abe36c4e4ac
glassfish-jaxb-api-2.2.12-8.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 4533ff42e7e841e1e1103d65a11509cc85a119c839109af0ff6df0c07b3a3e56
jackson-annotations-2.19.1-1.module+el8.2.0+23390+7631bd3f.src.rpm SHA-256: 6e8f19e9d20f94690bdadddec5f8784d2415f60e1099a0533b263e584c20d3f1
jackson-bom-2.19.1-1.module+el8.2.0+23390+7631bd3f.src.rpm SHA-256: 1cabe489897557923a3588e826f4594537772c30f054c8a345198a6275b38cfc
jackson-core-2.19.1-1.module+el8.2.0+23390+7631bd3f.src.rpm SHA-256: ddceafedf78ca8339ce4d458415e3919dd4aed70ecbe97e56c1f524482267226
jackson-databind-2.19.1-1.module+el8.2.0+23390+7631bd3f.src.rpm SHA-256: 2fde0357b3f54c106e7fe0c00d1968aa23868986d76f0849bb4b17b801862ace
jackson-jaxrs-providers-2.19.1-1.module+el8.2.0+23390+7631bd3f.src.rpm SHA-256: bdf961581bb00a79b34ae4f2c8e8187c882ed47160f4af7b7df95ac125ca8f4e
jackson-modules-base-2.19.1-1.module+el8.2.0+23390+7631bd3f.src.rpm SHA-256: d9268244fe9058a8a35c5d2dcd335d30d8cd879db104ec4e0a149dbbe118278a
jackson-parent-2.19.2-1.module+el8.2.0+23390+7631bd3f.src.rpm SHA-256: 87a5624280adf2391a3f8b0ad401c9a1039bfe0e169e9dab9666be0f482b575a
jakarta-commons-httpclient-3.1-28.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 50276786098d4b9f278949f2d29cc3f9c803519053acfd5446289741d61fa9be
javassist-3.18.1-8.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: f7758844e90881da0ab7cf51f23766930102407063cb133056781b8ec7cdd328
pki-servlet-engine-9.0.7-16.module+el8.2.0+23390+7631bd3f.2.src.rpm SHA-256: d252e25b551f2b18f4bf771019e133c33a11e777562f99bed7160075d7d949d8
python-nss-1.0.1-10.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 78de9422d12b295fa42e145dd6b9ba8fd9394ca98976199c70f4f03656242170
relaxngDatatype-2011.1-7.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 56290e8587b6a8a88ba2f7e05c7e629562889565430cd7d45622515ac3e7a1e0
resteasy-3.0.26-3.module+el8.2.0+23401+65186842.src.rpm SHA-256: e4e31ad8f1eb97480cc4efb546840fc847985e097fb6220cd012e0b1ea83fd46
slf4j-1.7.25-4.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 9658c2a5e83e3db3e37c4bc43de7cb3ccac3e07d814c64d8fd872e5cb3cdc0a2
stax-ex-1.7.7-8.module+el8.2.0+5723+4574fbff.src.rpm SHA-256: b1f9e5823d9629fb58bbb3722d40015b5e9c4a1acde507bdcb60fcd24f9ac806
velocity-1.7-24.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 2d66b2fc4920e5c656bc6b0cf0669634ae0854f3f5fbce481ba6b73c8fcba83f
xalan-j2-2.7.1-38.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: ebd234a3e289cbc121b7224bde246ae06348d0d1b5c763c54aa22b13389d93e3
xerces-j2-2.11.0-34.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 1e8befbd26490fbd854478e1ec42345ac6fbe56299797abcd0bc847536ba7c20
xml-commons-apis-1.4.01-25.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 13c235e3991694ed5d0b937514da067bc7ef249e5d3cd0b875e7468ec422688d
xml-commons-resolver-1.2-26.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 9be8f11924dfb904c88ca012ccd8ca45bbca025b54cfecf6f894a16385dee090
xmlstreambuffer-1.5.4-8.module+el8.2.0+5723+4574fbff.src.rpm SHA-256: 94083d7550925a1eecd68c53c168432d55afeb67d9bc0eae4a9545060b57df13
xsom-0-19.20110809svn.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 5c5c569ee17f3b125d907202af3940d3b870f49e205e6e3af7eca3b90357b1fd
x86_64
apache-commons-collections-3.2.2-10.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 61032ccfc3d125b1882c55dfc06101098b149aaaf78261f4d78104819b67e654
apache-commons-lang-2.6-21.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 324413ffde38b0e68fb4633ae751e74f06dd29d9845cc394dd75234a1c67534c
bea-stax-api-1.2.0-16.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 5698297dddd2ffe6cb398bf43338f3153040c3e47c40e7cd271fa88076240e11
fasterxml-oss-parent-69-1.module+el8.2.0+23390+7631bd3f.noarch.rpm SHA-256: d6e8a7b1bc07144142a59ba8d601aa2fc73a1858b111d0a48b3954cea6a702fa
glassfish-fastinfoset-1.2.13-9.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 59b0c5aee838fc3f60c471fd22a62c7bf7b3e7be3bc1e90f438d93652edae755
glassfish-jaxb-api-2.2.12-8.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 230eccdbf84113f5dce6f26c5da178a7234b43620e779f4a6c71a18aa3ded1aa
glassfish-jaxb-core-2.2.11-11.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: bf8be858f41d6742b74511b5f9ebacd9749a35c42c715c0d49ce7325de025926
glassfish-jaxb-runtime-2.2.11-11.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: ed75a05cd326da7ab45df8f813c9ee87e68b3633462ec01a5bd31ae362f9efce
glassfish-jaxb-txw2-2.2.11-11.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: ff5a17869359c38652f645729e2051008f7df309dfdb9d4546c054bcee255d44
jackson-annotations-2.19.1-1.module+el8.2.0+23390+7631bd3f.noarch.rpm SHA-256: 2e3de20ad53e4de4267538c1f3b631f04761dcffe3dde097715b1012f6a98223
jackson-bom-2.19.1-1.module+el8.2.0+23390+7631bd3f.noarch.rpm SHA-256: 8055cab6403fadbda0b3770729d6345aa442affec6a9615d3ba8b712561ea6e2
jackson-core-2.19.1-1.module+el8.2.0+23390+7631bd3f.noarch.rpm SHA-256: 6e8fdc25dd07ee1fcd8bfd3575f4db03af85cfbba0e7d2396635b07f092ebead
jackson-databind-2.19.1-1.module+el8.2.0+23390+7631bd3f.noarch.rpm SHA-256: 834e2183c94a3bad33de7d13719dd59fee938505495824fa2c9580e7d1106a49
jackson-jaxrs-json-provider-2.19.1-1.module+el8.2.0+23390+7631bd3f.noarch.rpm SHA-256: 2663b3cc5538474991c6245d8dae56a876b42b6e16cd6dcc46f2db76d38da019
jackson-jaxrs-providers-2.19.1-1.module+el8.2.0+23390+7631bd3f.noarch.rpm SHA-256: 3e0060fa079a8abae1305a8d3da8d6f46c70309eddb5ce122d77aee6a9bf591b
jackson-module-jaxb-annotations-2.19.1-1.module+el8.2.0+23390+7631bd3f.noarch.rpm SHA-256: ae21ede06f8a733f7a7f94e9540123894c2805f839268f787e85656ebdd41e25
jackson-modules-base-2.19.1-1.module+el8.2.0+23390+7631bd3f.noarch.rpm SHA-256: b54aaacad0351a1acd0594ef92e5fb5bebb6c3aa25d8e947a3c92670e3ab84c7
jackson-parent-2.19.2-1.module+el8.2.0+23390+7631bd3f.noarch.rpm SHA-256: 2def3f22483a651102f29d4665a85fe4718381bcbbd69cf783ca852730cf1ba6
jakarta-commons-httpclient-3.1-28.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 8086eed8f36137ac5f481057e0bcd04d0bf57f2c9bccc2bb0fc3feb06f574061
javassist-3.18.1-8.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 1e7af30426ec8abe97a466764f13ea870b51198b89ae774c1b61f4ac0cc3de72
javassist-javadoc-3.18.1-8.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: e740b18bb372f1986a598c5c04f0e7a2c985feca0d8178136870a6b838367cd5
pki-servlet-4.0-api-9.0.7-16.module+el8.2.0+23390+7631bd3f.2.noarch.rpm SHA-256: 23a6f183d50022855b00a47e4065c4b0daf26c5e5756cecf12b1be8d1ce33201
pki-servlet-engine-9.0.7-16.module+el8.2.0+23390+7631bd3f.2.noarch.rpm SHA-256: 3dc815eebdbc9006ab8b41f815a0c3a552c1ea48f89c5454746066ee0ea166db
python-nss-debugsource-1.0.1-10.module+el8.1.0+3366+6dfb954c.x86_64.rpm SHA-256: ca0fa12ad8c1c6931da5b67d2b85689244608021d7225c979c99476179e4a351
python-nss-doc-1.0.1-10.module+el8.1.0+3366+6dfb954c.x86_64.rpm SHA-256: c935d1b335fd1e997012840c5b6a4266f98a8d3f7787249d1e33d7dd89885050
python3-nss-1.0.1-10.module+el8.1.0+3366+6dfb954c.x86_64.rpm SHA-256: 1c608c8d2bd0112cae5ee7014691283b507158faee48874d25b484ca6a12b0cb
python3-nss-debuginfo-1.0.1-10.module+el8.1.0+3366+6dfb954c.x86_64.rpm SHA-256: e9f19ccf767699bc27c5828b2a96faaaa17917e88ce3dfc08e7ed1b92524791f
relaxngDatatype-2011.1-7.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 4e60603734ace48b089ee5fa3bd1a9901ccf8b8629bf1b4d2cf26ee8679bbea9
resteasy-3.0.26-3.module+el8.2.0+23401+65186842.noarch.rpm SHA-256: 30cae48b1946d781589fa285213379579eed80655b0c01c3ddb81e8bee950330
slf4j-1.7.25-4.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: cc1be6c45e1d7ca928f1ea9c364ac4df081815b6aa8a387fe4446e7e5d692247
slf4j-jdk14-1.7.25-4.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: f99f3a46b42e49d0cff136ee14e24bf860672bff91a86f11a32cb77b83755eb0
stax-ex-1.7.7-8.module+el8.2.0+5723+4574fbff.noarch.rpm SHA-256: b1f66a15afd3cd9a0a7dae91b1c444e21606f97f0de46eae1550e3ba589f063e
velocity-1.7-24.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 9e0da98978f2f63fcec18fd782a216e08964fb793b5b603b0a741688a684cda9
xalan-j2-2.7.1-38.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 0a2694c77779180120ec2677e5be800100697ebe3c8936a98de856e4ee9bf9e7
xerces-j2-2.11.0-34.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: b1a1e0ebaf0648f6f29c236349bcbc53cbc541a94b8fdf62932721868e646096
xml-commons-apis-1.4.01-25.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: f3b74c7d7f096e2a503458ddcec76f07503454b51b5699c16d14268974c70e93
xml-commons-resolver-1.2-26.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: f13cb197c25c7a746b7aedb57778e8e360356e15626333d2b6f545daea419ac3
xmlstreambuffer-1.5.4-8.module+el8.2.0+5723+4574fbff.noarch.rpm SHA-256: 4b575b0866cbd9ea424c17a4fb841162bd826795d96cce2d06e9d17523748173
xsom-0-19.20110809svn.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 95e07aabb2e7c76f7a71613a1e399b7f850b955439e54a1e4edff1e458f5fa3f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility