Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 38 BorgBackup 2023-555f9fac30 Critical: Spoofing Issue Fix

fedora
Calendar Grey September 15, 2023
Dist Fedora Esm H88
BorgBackup 1.2.6 addresses an archive spoofing vulnerability in Fedora 38 that risked data loss. Ensure your backups are protected by updating today.
fix for CVE-2023-36811: spoofed archive leads to data loss Please note that starting with borgbackup 1.2.5 all borg repos must use TAM authentication: https://github.com/borgbackup...

Summary

BorgBackup (short: Borg) is a deduplicating backup program. Optionally, it

supports compression and authenticated encryption.

Update Information:

fix for CVE-2023-36811: spoofed archive leads to data loss Please note that starting with borgbackup 1.2.5 all borg repos must use TAM authentication: https://github.com/borgbackup/borg/blob/1.2.6/docs/changes.rst#pre-125-archives- spoofing-vulnerability-cve-2023-36811

Change Log

* Tue Sep 5 2023 Felix Schwarz - 1.2.6-1 - update to 1.2.6 to fix CVE-2023-36811 - rely on auto-generated version requirement for msgpack

References


[ 1 ] Bug #2236305 - CVE-2023-36811 borgbackup: spoofed archive leads to data loss [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2236305

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-555f9fac30' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: borgbackup
Product: Fedora 38
Version: 1.2.6
Release: 1.fc38
Summary: A deduplicating backup program with compression and authenticated encryption

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here