Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Fedora 38: FEDORA-2024-b93312a597 Critical: Syncthing Memory Exhaustion

fedora
Calendar Grey February 21, 2024
Dist Fedora Esm H88
The latest Syncthing 1.27.3 has been released for Fedora 38, fixing critical memory leaks in the QUIC protocol. Visit the official Syncthing docs for details.
Update to version 1.27.3

Summary

Syncthing replaces other file synchronization services with something

open, trustworthy and decentralized. Your data is your data alone and

you deserve to choose where it is stored, if it is shared with some

third party and how it's transmitted over the Internet. Using syncthing,

that control is returned to you.

This package contains the syncthing client binary and systemd services.

Update Information:

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

Change Log

* Mon Feb 12 2024 Fabio Valentini - 1.27.3-1 - Update to version 1.27.3; Fixes RHBZ#2263121

References


[ 1 ] Bug #2257833 - CVE-2023-49295 syncthing: quic-go: memory exhaustion attack against QUIC's path validation mechanism [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257833

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b93312a597' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: syncthing
Product: Fedora 38
Version: 1.27.3
Release: 1.fc38
Summary: Continuous File Synchronization

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here