Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Fedora 39: 2024-ff98facbc6 moderate: rustls-native-certs DoS

fedora
Calendar Grey October 19, 2024
Scroller Fedora
Debian patches for rust-rustls-native-certs include critical safeguards addressing possible DoS vulnerabilities. Key enhancements and improved compatibility introduced!
Update the hyper-rustls crate to version 0.27.3

Summary

Rustls-native-certs allows rustls to use the platform native certificate

store.

Update Information:

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3. Update the tower crate to version 0.5.1 and add a compat package for version 0.4. Update the tower-http crate to version 0.6.1 and add a compat package for version 0.5.

Change Log

* Wed Oct 9 2024 Fabio Valentini - 0.7.3-1 - Initial import (rustls-native-certs 0.7 compat package)

References


[ 1 ] Bug #2316020 - CVE-2024-47609 rust-tonic: Remotely exploitable DoS in Tonic `<=v0.12.2` [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2316020

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ff98facbc6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: rust-rustls-native-certs0.7
Product: Fedora 39
Version: 0.7.3
Release: 1.fc39
Summary: Allows rustls to use the platform native certificate store

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.