Red Hat Security Advisory: python-kdcproxy security update
Two security vulnerabilities have been identified in the python-kdcproxy component of Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The first is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability via realm-controlled DNS SRV records (CVE-2025-59088). The second is a remote Denial of Service (DoS) vulnerability caused by unbounded TCP upstream buffering (CVE-2025-59089). Red Hat has released an important security update addressing these issues for multiple architectures including x86_64, ppc64le, aarch64, and s390x. Users of affected Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions should apply the update to mitigate these vulnerabilities.
AI Analysis
Technical Summary
Red Hat Product Security has issued an important security advisory (RHSA-2025:21806) for python-kdcproxy in Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The advisory addresses two vulnerabilities: CVE-2025-59088, an unauthenticated SSRF vulnerability via realm-controlled DNS SRV records, and CVE-2025-59089, a remote Denial of Service vulnerability due to unbounded TCP upstream buffering. These vulnerabilities affect python-kdcproxy version 1.0.0-7.el9_0.1 and related packages for multiple architectures. The advisory provides updated packages to fix these issues. No CVSS scores are provided in the advisory, but the severity is rated as important by Red Hat. The advisory references Red Hat knowledge base article 11258 for update instructions and provides SHA-256 hashes for the fixed packages.
Potential Impact
The SSRF vulnerability (CVE-2025-59088) allows an unauthenticated attacker to induce the python-kdcproxy component to make unintended network requests based on manipulated DNS SRV records, potentially leading to information disclosure or further attacks. The remote DoS vulnerability (CVE-2025-59089) can cause service disruption by exhausting resources through unbounded TCP upstream buffering. Both vulnerabilities impact the availability and security of systems running the affected python-kdcproxy versions in Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.
Mitigation Recommendations
Red Hat has released updated python-kdcproxy packages that address these vulnerabilities. Users should apply the security update RHSA-2025:21806 promptly to remediate these issues. Detailed update instructions are available at https://access.redhat.com/articles/11258. No additional mitigations or workarounds are specified in the advisory. Systems running the affected versions should be updated to the fixed package versions provided by Red Hat.
Red Hat Security Advisory: python-kdcproxy security update
Description
Two security vulnerabilities have been identified in the python-kdcproxy component of Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The first is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability via realm-controlled DNS SRV records (CVE-2025-59088). The second is a remote Denial of Service (DoS) vulnerability caused by unbounded TCP upstream buffering (CVE-2025-59089). Red Hat has released an important security update addressing these issues for multiple architectures including x86_64, ppc64le, aarch64, and s390x. Users of affected Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions should apply the update to mitigate these vulnerabilities.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat Product Security has issued an important security advisory (RHSA-2025:21806) for python-kdcproxy in Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The advisory addresses two vulnerabilities: CVE-2025-59088, an unauthenticated SSRF vulnerability via realm-controlled DNS SRV records, and CVE-2025-59089, a remote Denial of Service vulnerability due to unbounded TCP upstream buffering. These vulnerabilities affect python-kdcproxy version 1.0.0-7.el9_0.1 and related packages for multiple architectures. The advisory provides updated packages to fix these issues. No CVSS scores are provided in the advisory, but the severity is rated as important by Red Hat. The advisory references Red Hat knowledge base article 11258 for update instructions and provides SHA-256 hashes for the fixed packages.
Potential Impact
The SSRF vulnerability (CVE-2025-59088) allows an unauthenticated attacker to induce the python-kdcproxy component to make unintended network requests based on manipulated DNS SRV records, potentially leading to information disclosure or further attacks. The remote DoS vulnerability (CVE-2025-59089) can cause service disruption by exhausting resources through unbounded TCP upstream buffering. Both vulnerabilities impact the availability and security of systems running the affected python-kdcproxy versions in Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.
Mitigation Recommendations
Red Hat has released updated python-kdcproxy packages that address these vulnerabilities. Users should apply the security update RHSA-2025:21806 promptly to remediate these issues. Detailed update instructions are available at https://access.redhat.com/articles/11258. No additional mitigations or workarounds are specified in the advisory. Systems running the affected versions should be updated to the fixed package versions provided by Red Hat.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:21806
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-59089"]
Threat ID: 6a419cab27e9c79719ab8fba
Added to database: 06/28/2026, 22:14:03 UTC
Last enriched: 06/28/2026, 22:20:04 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.