Gvisor-Tap-Vsock security updates for AlmaLinux

Published by

AlmaLinux has announced the release of updated gvisor-tap-vsock packages for both AlmaLinux 9 and 10, addressing moderate-severity security vulnerabilities. The updates, identified as ALSA-2025:9151 for version 10 and ALSA-2025:9150 for version 9, were released on June 17, 2025.

Summary of Updates:
- gvisor-tap-vsock serves as a replacement for libslirp and VPNKit and is developed in pure Go, leveraging the gVisor network stack. This update introduces features such as a configurable DNS server and dynamic port forwarding, enhancing functionality compared to its predecessor, libslirp.

Security Fixes:
- Both updates address a critical security issue related to request smuggling in the net/http package due to the acceptance of invalid chunked data, identified by CVE-2025-22871.

For users seeking more information about the vulnerabilities, including their impact and CVSS scores, detailed references can be found on the CVE pages linked in the official announcements.

Additional Information:
Users are encouraged not to reply directly to the automated email. Instead, they can reach out to the AlmaLinux community via chat for further inquiries or manage their notification settings through the AlmaLinux mailing list platform.

Extension:
As cyber threats continue to evolve, it is vital for users of AlmaLinux to keep their systems updated with the latest security patches. Regular monitoring of security updates, participation in community discussions, and proactive management of notification settings can enhance overall system security. Users should also consider evaluating their current implementations of gvisor-tap-vsock to fully leverage its new features while ensuring that any potential vulnerabilities are promptly addressed

Gvisor-Tap-Vsock security updates for AlmaLinux

Updated gvisor-tap-vsock packages are available for AlmaLinux 9 and 10:

ALSA-2025:9151: gvisor-tap-vsock security update (Moderate)
ALSA-2025:9150: gvisor-tap-vsock security update (Moderate)

Gvisor-Tap-Vsock security updates for AlmaLinux @ Linux Compatible