Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:8336 - Security Advisory
Issued:
2025-06-02
Updated:
2025-06-02

RHSA-2025:8336 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: varnish:6 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the varnish:6 module is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don't have to create the same web page over and over again, giving the website a significant speed up.

Security Fix(es):

  • varnish: request smuggling attacks (CVE-2025-47905)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2364235 - CVE-2025-47905 varnish: request smuggling attacks

CVEs

  • CVE-2025-47905

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
varnish-6.0.13-1.module+el8.10.0+23111+831cc069.1.src.rpm SHA-256: 143da31b0fe7f1aa7adf3505cd1aee505488db6bb4633bb28bc214ffa4f95483
varnish-modules-0.15.0-6.module+el8.10.0+21682+bcdd3a30.src.rpm SHA-256: 816b1d6d80ea880ba225c1a044f996ebd34eef1bc73665010ad9ce709992dee9
x86_64
varnish-6.0.13-1.module+el8.10.0+23111+831cc069.1.x86_64.rpm SHA-256: d7a3200157573be260ff200e9db4783b9f7bc17f4123e31aea2b431f6d93d557
varnish-devel-6.0.13-1.module+el8.10.0+23111+831cc069.1.x86_64.rpm SHA-256: 5be7c2c05d10198167209a7770289b6b94910aba03e014e816d964ba041b4de4
varnish-docs-6.0.13-1.module+el8.10.0+23111+831cc069.1.x86_64.rpm SHA-256: db07df529f33741dbad3570c22d02a72caf72427ee2dfbca04fffdab67f53ab5
varnish-modules-0.15.0-6.module+el8.10.0+21682+bcdd3a30.x86_64.rpm SHA-256: 2dddb3e4c4682d3db8ae4f4a05d458727f50d2f93e76b6289abeec430e81c71d
varnish-modules-debuginfo-0.15.0-6.module+el8.10.0+21682+bcdd3a30.x86_64.rpm SHA-256: 8db837a4b93094173c893c9f644722d886b46d5be802152fa1cb07a08b7aefa3
varnish-modules-debugsource-0.15.0-6.module+el8.10.0+21682+bcdd3a30.x86_64.rpm SHA-256: 2b36c47e1322160d1678f8ef1e35d8565e3c1f0eac5b9ef80221fc8c8a5f9064

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
varnish-6.0.13-1.module+el8.10.0+23111+831cc069.1.src.rpm SHA-256: 143da31b0fe7f1aa7adf3505cd1aee505488db6bb4633bb28bc214ffa4f95483
varnish-modules-0.15.0-6.module+el8.10.0+21682+bcdd3a30.src.rpm SHA-256: 816b1d6d80ea880ba225c1a044f996ebd34eef1bc73665010ad9ce709992dee9
s390x
varnish-6.0.13-1.module+el8.10.0+23111+831cc069.1.s390x.rpm SHA-256: 7d5e483c02748297525ec9189fa90304c2cda19eef692a9a53d36672548644a8
varnish-devel-6.0.13-1.module+el8.10.0+23111+831cc069.1.s390x.rpm SHA-256: e9c58284ec7d5285211275f3ff30cf3593e5a48fb3662c3acb52bd16433a3272
varnish-docs-6.0.13-1.module+el8.10.0+23111+831cc069.1.s390x.rpm SHA-256: 95d764b5d5abf91892a8469a44c7e951145850a181e842c676ff103b6fed3a32
varnish-modules-0.15.0-6.module+el8.10.0+21682+bcdd3a30.s390x.rpm SHA-256: 0aec598762e1a0c9eb3d9d202f440485fc03b3cf2d57065e8dfa027766493d24
varnish-modules-debuginfo-0.15.0-6.module+el8.10.0+21682+bcdd3a30.s390x.rpm SHA-256: e54a24e1d93888923084dfd3e06eab3e7aed7fa85ea2d4f088014d3a59973677
varnish-modules-debugsource-0.15.0-6.module+el8.10.0+21682+bcdd3a30.s390x.rpm SHA-256: 3154c9c15c21ed4616625615f85db115986db91a3ac91911c5c0a7d7f4d13680

Red Hat Enterprise Linux for Power, little endian 8

SRPM
varnish-6.0.13-1.module+el8.10.0+23111+831cc069.1.src.rpm SHA-256: 143da31b0fe7f1aa7adf3505cd1aee505488db6bb4633bb28bc214ffa4f95483
varnish-modules-0.15.0-6.module+el8.10.0+21682+bcdd3a30.src.rpm SHA-256: 816b1d6d80ea880ba225c1a044f996ebd34eef1bc73665010ad9ce709992dee9
ppc64le
varnish-6.0.13-1.module+el8.10.0+23111+831cc069.1.ppc64le.rpm SHA-256: 25e1b7b161a7b418f37d2a45b0439a4fb5c0bb1591ae36a411bd332844f3cb04
varnish-devel-6.0.13-1.module+el8.10.0+23111+831cc069.1.ppc64le.rpm SHA-256: 5c08246efb581c4ed7c7e1bbaafb33b5ec9b3517cf6df60de8fd5c8f5f11cffb
varnish-docs-6.0.13-1.module+el8.10.0+23111+831cc069.1.ppc64le.rpm SHA-256: ab2674824a7ae95efb8f48a0fd033e25c8d93ba5f60a0eabe1822c043fa09a10
varnish-modules-0.15.0-6.module+el8.10.0+21682+bcdd3a30.ppc64le.rpm SHA-256: 6461765756a43d068e7e839d3637d648c173ed668ec58e32ddc13330fd241ea8
varnish-modules-debuginfo-0.15.0-6.module+el8.10.0+21682+bcdd3a30.ppc64le.rpm SHA-256: be9786aa29e950e484c114a5e94d70b66a76e6440fcf79a94ea1ac42879228d8
varnish-modules-debugsource-0.15.0-6.module+el8.10.0+21682+bcdd3a30.ppc64le.rpm SHA-256: 3a27797c58717be84977e8b9bc14445ef551f997e1c89333d11e15a115ee0e73

Red Hat Enterprise Linux for ARM 64 8

SRPM
varnish-6.0.13-1.module+el8.10.0+23111+831cc069.1.src.rpm SHA-256: 143da31b0fe7f1aa7adf3505cd1aee505488db6bb4633bb28bc214ffa4f95483
varnish-modules-0.15.0-6.module+el8.10.0+21682+bcdd3a30.src.rpm SHA-256: 816b1d6d80ea880ba225c1a044f996ebd34eef1bc73665010ad9ce709992dee9
aarch64
varnish-6.0.13-1.module+el8.10.0+23111+831cc069.1.aarch64.rpm SHA-256: 6deef42cd11ef253ab8fde7c4757c08fb9fd2b87be1da77847a2d0b8e739f154
varnish-devel-6.0.13-1.module+el8.10.0+23111+831cc069.1.aarch64.rpm SHA-256: ce370579a9581aae6e2bb60434defe45755bb4ce19eea3378b5c7eff88bb5501
varnish-docs-6.0.13-1.module+el8.10.0+23111+831cc069.1.aarch64.rpm SHA-256: 2444dac3382bef57bc2c6a3f7931fcca2f9416cb8665bc230b0ba361647a0db8
varnish-modules-0.15.0-6.module+el8.10.0+21682+bcdd3a30.aarch64.rpm SHA-256: bcbe0e4f35cd4df42ecca5dac6ce19d83381dbfa1f2ee41a705a341cd5ab3b9c
varnish-modules-debuginfo-0.15.0-6.module+el8.10.0+21682+bcdd3a30.aarch64.rpm SHA-256: 98494f77a73a7e37b0166646d71ba277556cd1e9e6dc09aecf10ceb19046a85a
varnish-modules-debugsource-0.15.0-6.module+el8.10.0+21682+bcdd3a30.aarch64.rpm SHA-256: bf0d8e4fd1f3d7350843281aceaa506d92d969a3b0ddb2137f92db8c132076d5

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility