Synopsis
Important: opentelemetry-collector security update
Type/Severity
Security Advisory: Important
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for opentelemetry-collector is now available for Red Hat Enterprise Linux 10.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Collector with the supported components for a Red Hat build of OpenTelemetry
Security Fix(es):
- crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 10 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 10 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x
-
Red Hat Enterprise Linux for Power, little endian 10 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le
-
Red Hat Enterprise Linux for ARM 64 10 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x
-
Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le
-
Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x
Fixes
-
BZ - 2418462
- CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 10
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| x86_64 |
|
opentelemetry-collector-0.135.0-3.el10_1.x86_64.rpm
|
SHA-256: 4c6a79ee997bef294e94d17b53cbe5115057e506fd49c5b397496eafb72905ba |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| x86_64 |
|
opentelemetry-collector-0.135.0-3.el10_1.x86_64.rpm
|
SHA-256: 4c6a79ee997bef294e94d17b53cbe5115057e506fd49c5b397496eafb72905ba |
Red Hat Enterprise Linux for IBM z Systems 10
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| s390x |
|
opentelemetry-collector-0.135.0-3.el10_1.s390x.rpm
|
SHA-256: bf874057a9433c745558e32242f257db398306c06964b3445c6269d6d58212b3 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| s390x |
|
opentelemetry-collector-0.135.0-3.el10_1.s390x.rpm
|
SHA-256: bf874057a9433c745558e32242f257db398306c06964b3445c6269d6d58212b3 |
Red Hat Enterprise Linux for Power, little endian 10
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| ppc64le |
|
opentelemetry-collector-0.135.0-3.el10_1.ppc64le.rpm
|
SHA-256: 3b7f4e74d32cfc727717f2ebd14a5a740442ffec5ed43ae4b2635dc35c44591c |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| ppc64le |
|
opentelemetry-collector-0.135.0-3.el10_1.ppc64le.rpm
|
SHA-256: 3b7f4e74d32cfc727717f2ebd14a5a740442ffec5ed43ae4b2635dc35c44591c |
Red Hat Enterprise Linux for ARM 64 10
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| aarch64 |
|
opentelemetry-collector-0.135.0-3.el10_1.aarch64.rpm
|
SHA-256: 272c6af13b56b7501a52ba7c83b06f9c98d05797f2f89b19a069c792e5b33e65 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| aarch64 |
|
opentelemetry-collector-0.135.0-3.el10_1.aarch64.rpm
|
SHA-256: 272c6af13b56b7501a52ba7c83b06f9c98d05797f2f89b19a069c792e5b33e65 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| aarch64 |
|
opentelemetry-collector-0.135.0-3.el10_1.aarch64.rpm
|
SHA-256: 272c6af13b56b7501a52ba7c83b06f9c98d05797f2f89b19a069c792e5b33e65 |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| s390x |
|
opentelemetry-collector-0.135.0-3.el10_1.s390x.rpm
|
SHA-256: bf874057a9433c745558e32242f257db398306c06964b3445c6269d6d58212b3 |
Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| ppc64le |
|
opentelemetry-collector-0.135.0-3.el10_1.ppc64le.rpm
|
SHA-256: 3b7f4e74d32cfc727717f2ebd14a5a740442ffec5ed43ae4b2635dc35c44591c |
Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| x86_64 |
|
opentelemetry-collector-0.135.0-3.el10_1.x86_64.rpm
|
SHA-256: 4c6a79ee997bef294e94d17b53cbe5115057e506fd49c5b397496eafb72905ba |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| x86_64 |
|
opentelemetry-collector-0.135.0-3.el10_1.x86_64.rpm
|
SHA-256: 4c6a79ee997bef294e94d17b53cbe5115057e506fd49c5b397496eafb72905ba |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| aarch64 |
|
opentelemetry-collector-0.135.0-3.el10_1.aarch64.rpm
|
SHA-256: 272c6af13b56b7501a52ba7c83b06f9c98d05797f2f89b19a069c792e5b33e65 |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| ppc64le |
|
opentelemetry-collector-0.135.0-3.el10_1.ppc64le.rpm
|
SHA-256: 3b7f4e74d32cfc727717f2ebd14a5a740442ffec5ed43ae4b2635dc35c44591c |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2
| SRPM |
|
opentelemetry-collector-0.135.0-3.el10_1.src.rpm
|
SHA-256: 9f534f577f8535bf80e091fc75b9de6a4e322ee2658377cebbaf7ed92b936cef |
| s390x |
|
opentelemetry-collector-0.135.0-3.el10_1.s390x.rpm
|
SHA-256: bf874057a9433c745558e32242f257db398306c06964b3445c6269d6d58212b3 |