Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 37: FEDORA-2023-2a9214af5f Critical Proxygen DDoS Threat

fedora
Calendar Grey October 24, 2023
Dist Fedora Esm H88
Fedora has released an update for the fbthrift package, which resolves security concerns related to proxygen, notably a severe vulnerability that could lead to DDoS attacks.
Update Folly stack to the latest 2023.10.16.00 tag proxygen: Security fix for CVE-2023-44487

Summary

Thrift is a serialization and RPC framework for service communication. Thrift

enables these features in all major languages, and there is strong support for

C++, Python, Hack, and Java. Most services at Facebook are written using Thrift

for RPC, and some storage systems use Thrift for serializing records on disk.

Facebook Thrift is not a distribution of Apache Thrift. This is an evolved

internal branch of Thrift that Facebook re-released to open source community in

February 2014. Facebook Thrift was originally released closely tracking Apache

Thrift but is now evolving in new directions. In particular, the compiler was

rewritten from scratch and the new implementation features a fully asynchronous

Thrift server.

Update Information:

Update Folly stack to the latest 2023.10.16.00 tag proxygen: Security fix for CVE-2023-44487

Change Log

* Wed Oct 18 2023 Michel Lind - 2023.10.16.00-1 - Update to 2023.10.16.00 * Tue Oct 17 2023 Michel Lind - 2023.10.09.00-1 - Update to 2023.10.09.00 * Thu Oct 5 2023 Remi Collet - 2023.09.11.00-3 - rebuild for new libsodium * Tue Sep 12 2023 Michel Lind - 2023.09.11.00-2 - Fix undefined reference to EventHandlerRuntime * Tue Sep 12 2023 Michel Lind - 2023.09.11.00-1 - Update to 2023.09.11.00 * Wed Jul 19 2023 Fedora Release Engineering - 2023.07.03.00-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jul 6 2023 Michel Alexandre Salim - 2023.07.03.00-1 - Update to 2023.07.03.00 - Use SPDX license identifier * Wed Jun 28 2023 Vitaly Zaitsev - 2023.04.24.00-2 - Rebuilt due to fmt 10 update.

References


[ 1 ] Bug #2221799 - mcrouter-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2221799 [ 2 ] Bug #2239431 - proxygen-2023.10.16.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239431 [ 3 ] Bug #2239594 - wangle-2023.10.16.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239594 [ 4 ] Bug #2239613 - fb303-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239613 [ 5 ] Bug #2239614 - fbthrift-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239614 [ 6 ] Bug #2239623 - fizz-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239623 [ 7 ] Bug #2239624 - folly-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239624 [ 8 ] Bug #2243253 - [Major Incident] CVE-2023-44487 proxygen: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) ...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-2a9214af5f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: fbthrift
Product: Fedora 37
Version: 2023.10.16.00
Release: 1.fc37
Summary: Facebook's branch of Apache Thrift, including a new C++ server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here