Synopsis
Important: opentelemetry-collector security update
Type/Severity
Security Advisory: Important
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for opentelemetry-collector is now available for Red Hat Enterprise Linux 9.6 Extended Update Support.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Collector with the supported components for a Red Hat build of OpenTelemetry
Security Fix(es):
- github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation (CVE-2025-68156)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
-
Red Hat Enterprise Linux Server - AUS 9.6 x86_64
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x
Fixes
-
BZ - 2422891
- CVE-2025-68156 github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| x86_64 |
|
opentelemetry-collector-0.135.0-2.el9_6.x86_64.rpm
|
SHA-256: 2e17e712a374531eaf8fd1d64b70efb86103d755929c529bdacfc14e488e7aa6 |
Red Hat Enterprise Linux Server - AUS 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| x86_64 |
|
opentelemetry-collector-0.135.0-2.el9_6.x86_64.rpm
|
SHA-256: 2e17e712a374531eaf8fd1d64b70efb86103d755929c529bdacfc14e488e7aa6 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| s390x |
|
opentelemetry-collector-0.135.0-2.el9_6.s390x.rpm
|
SHA-256: 2d7b78075945a95f8ad834bf5521032c69309bcfe88f7844737a89d24f5eb5b6 |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| ppc64le |
|
opentelemetry-collector-0.135.0-2.el9_6.ppc64le.rpm
|
SHA-256: 6acc94d87f2a994a715095dd4fd728f88d1edbc8887427ef6d3962511fb020c2 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| aarch64 |
|
opentelemetry-collector-0.135.0-2.el9_6.aarch64.rpm
|
SHA-256: 732faebb948c830e36026d5de818ea601fb73fec182b76136af6692f0a90a11d |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| ppc64le |
|
opentelemetry-collector-0.135.0-2.el9_6.ppc64le.rpm
|
SHA-256: 6acc94d87f2a994a715095dd4fd728f88d1edbc8887427ef6d3962511fb020c2 |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| x86_64 |
|
opentelemetry-collector-0.135.0-2.el9_6.x86_64.rpm
|
SHA-256: 2e17e712a374531eaf8fd1d64b70efb86103d755929c529bdacfc14e488e7aa6 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| aarch64 |
|
opentelemetry-collector-0.135.0-2.el9_6.aarch64.rpm
|
SHA-256: 732faebb948c830e36026d5de818ea601fb73fec182b76136af6692f0a90a11d |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| s390x |
|
opentelemetry-collector-0.135.0-2.el9_6.s390x.rpm
|
SHA-256: 2d7b78075945a95f8ad834bf5521032c69309bcfe88f7844737a89d24f5eb5b6 |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| x86_64 |
|
opentelemetry-collector-0.135.0-2.el9_6.x86_64.rpm
|
SHA-256: 2e17e712a374531eaf8fd1d64b70efb86103d755929c529bdacfc14e488e7aa6 |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| aarch64 |
|
opentelemetry-collector-0.135.0-2.el9_6.aarch64.rpm
|
SHA-256: 732faebb948c830e36026d5de818ea601fb73fec182b76136af6692f0a90a11d |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| ppc64le |
|
opentelemetry-collector-0.135.0-2.el9_6.ppc64le.rpm
|
SHA-256: 6acc94d87f2a994a715095dd4fd728f88d1edbc8887427ef6d3962511fb020c2 |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6
| SRPM |
|
opentelemetry-collector-0.135.0-2.el9_6.src.rpm
|
SHA-256: 099971a64b961bd3fe22e832fe52775db08090e3c88230891497749dfc565632 |
| s390x |
|
opentelemetry-collector-0.135.0-2.el9_6.s390x.rpm
|
SHA-256: 2d7b78075945a95f8ad834bf5521032c69309bcfe88f7844737a89d24f5eb5b6 |