Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Fedora 36 FEDORA-2022-5d37367673 Critical Capnproto Security Fix

fedora
Calendar Grey December 3, 2022
Dist Fedora Esm H88
Upgrade capnproto to mitigate an out-of-bounds read vulnerability identified in Fedora 36 under the security advisory reference CVE-2022-46149.
Update capnproto to version 0.9.2 to address CVE-2022-46149

Summary

rr is a lightweight tool for recording and replaying execution

of applications (trees of processes and threads).

For more information, please visit https://rr-project.org/

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages

were rebuilt for both the fix for the security issue and the capnproto SONAME

bump.

* Fri Dec 2 2022 Fabio Valentini - 5.6.0-2

- Rebuild for capnproto 0.9.2 / CVE-2022-46149

[ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2150076

su -c 'dnf upgrade --advisory FEDORA-2022-5d37367673' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 36
Version: 5.6.0
Release: 2.fc36
Summary: Tool to record and replay execution of applications

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here