Synopsis
Important: opentelemetry-collector security update
Type/Severity
Security Advisory: Important
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for opentelemetry-collector is now available for Red Hat Enterprise Linux 9.4 Extended Update Support.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Collector with the supported components for a Red Hat build of OpenTelemetry
Security Fix(es):
- golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
-
Red Hat Enterprise Linux Server - AUS 9.4 x86_64
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x
Fixes
-
BZ - 2354195
- CVE-2025-30204 golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| x86_64 |
|
opentelemetry-collector-0.107.0-8.el9_4.x86_64.rpm
|
SHA-256: c977cfac08156c481c3b3a93d8798853625326bb00b0eb953a5de44a67fa456d |
Red Hat Enterprise Linux Server - AUS 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| x86_64 |
|
opentelemetry-collector-0.107.0-8.el9_4.x86_64.rpm
|
SHA-256: c977cfac08156c481c3b3a93d8798853625326bb00b0eb953a5de44a67fa456d |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| s390x |
|
opentelemetry-collector-0.107.0-8.el9_4.s390x.rpm
|
SHA-256: db9718f74e320e241ebe4bd325e1cdfd26565c6e4d99201f5125ea004e4e91db |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| ppc64le |
|
opentelemetry-collector-0.107.0-8.el9_4.ppc64le.rpm
|
SHA-256: 2163e007cce00d43a43700eb17dffb6a4f8de63708b82ce6d55b3cdd146c8b0b |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| aarch64 |
|
opentelemetry-collector-0.107.0-8.el9_4.aarch64.rpm
|
SHA-256: 16f623a12ce5e070cce59e8a9b0af6409b7469c639646d766c2a4d47b1b63bcf |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| ppc64le |
|
opentelemetry-collector-0.107.0-8.el9_4.ppc64le.rpm
|
SHA-256: 2163e007cce00d43a43700eb17dffb6a4f8de63708b82ce6d55b3cdd146c8b0b |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| x86_64 |
|
opentelemetry-collector-0.107.0-8.el9_4.x86_64.rpm
|
SHA-256: c977cfac08156c481c3b3a93d8798853625326bb00b0eb953a5de44a67fa456d |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| aarch64 |
|
opentelemetry-collector-0.107.0-8.el9_4.aarch64.rpm
|
SHA-256: 16f623a12ce5e070cce59e8a9b0af6409b7469c639646d766c2a4d47b1b63bcf |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| s390x |
|
opentelemetry-collector-0.107.0-8.el9_4.s390x.rpm
|
SHA-256: db9718f74e320e241ebe4bd325e1cdfd26565c6e4d99201f5125ea004e4e91db |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| x86_64 |
|
opentelemetry-collector-0.107.0-8.el9_4.x86_64.rpm
|
SHA-256: c977cfac08156c481c3b3a93d8798853625326bb00b0eb953a5de44a67fa456d |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| aarch64 |
|
opentelemetry-collector-0.107.0-8.el9_4.aarch64.rpm
|
SHA-256: 16f623a12ce5e070cce59e8a9b0af6409b7469c639646d766c2a4d47b1b63bcf |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| ppc64le |
|
opentelemetry-collector-0.107.0-8.el9_4.ppc64le.rpm
|
SHA-256: 2163e007cce00d43a43700eb17dffb6a4f8de63708b82ce6d55b3cdd146c8b0b |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4
| SRPM |
|
opentelemetry-collector-0.107.0-8.el9_4.src.rpm
|
SHA-256: 85dde082b7a08fcc62b3b64ee73231986c7ec1b00b2e31f14d88458f426c9c59 |
| s390x |
|
opentelemetry-collector-0.107.0-8.el9_4.s390x.rpm
|
SHA-256: db9718f74e320e241ebe4bd325e1cdfd26565c6e4d99201f5125ea004e4e91db |