Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Fedora 35: FEDORA-2021-9fde3d7ab1 Critical: DoS Eventlet Mitigation

fedora
Calendar Grey May 24, 2021
Dist Fedora Esm H88
To tackle the python-eventlet DoS vulnerabilities in Fedora related to CVE-2021-21419, it's crucial to keep informed about the provided solutions!
Mitigation for CVE-2021-21419 See: https://github.com/eventlet/eventlet/security/advisories/GHSA-9p9m-jm8w-94p2 for more details.

Summary

Eventlet is a networking library written in Python. It achieves high

scalability by using non-blocking io while at the same time retaining

high programmer usability by using coroutines to make the non-blocking

io operations appear blocking at the source code level.

Mitigation for CVE-2021-21419 See:

https://github.com/eventlet/eventlet/security/advisories/GHSA-9p9m-jm8w-94p2 for

more details.

* Sun May 16 2021 Kevin Fenzi - 0.31.0-1

- Update to 0.31.0. Fixes rhbz#1957249

- Mitigates CVE-2021-21419

* Sun Mar 7 2021 Kevin Fenzi - 0.30.2-1

- Update to 0.30.2. Fixes rhbz#1934511

[ 1 ] Bug #1958408 - CVE-2021-21419 python-eventlet: improper handling of highly compressed data and memory allocation with excessive size allows DoS [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1958408

su -c 'dnf upgrade --advisory FEDORA-2021-9fde3d7ab1' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 0.31.0
Release: 1.fc33
Summary: Highly concurrent networking library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here