Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 38: FEDORA-2024-38faa9a2a8 Critical: libell Auth Bypass

fedora
Calendar Grey March 8, 2024
Dist Fedora Esm H88
Crucial Fedora patch for libell resolves connectivity delays and improves integrated performance.
iwd 2.15: Fix issue with notice events for connection timeouts

Summary

The Embedded Linux* Library (ELL) provides core, low-level functionality for

system daemons. It typically has no dependencies other than the Linux kernel, C

standard library, and libdl (for dynamic linking). While ELL is designed to be

efficient and compact enough for use on embedded Linux platforms, it is not

limited to resource-constrained systems.

Update Information:

iwd 2.15: Fix issue with notice events for connection timeouts. Fix issue with reason code and deauthenticate event. Fix issue with handling basename() functionality. libell 0.63: Fix issue with handling ending boundary of the PEM.

Change Log

* Wed Feb 28 2024 Peter Robinson - 0.63-1 - Update to 0.63 * Sat Feb 10 2024 Peter Robinson - 0.62-1 - Update to 0.62 * Thu Jan 25 2024 Fedora Release Engineering - 0.61-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 0.61-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Mon Jan 8 2024 Davide Caratti - 0.61-2 - Change specfile to use SPDX identifier

References


[ 1 ] Bug #2264597 - TRIAGE CVE-2023-52161 iwd: potential authorization bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2264597

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-38faa9a2a8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libell
Product: Fedora 38
Version: 0.63
Release: 1.fc38
URL:
Summary: Embedded Linux library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here