Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 39: FEDORA-2024-ff98facbc6 critical: rust-tower DoS exploit

fedora
Calendar Grey October 19, 2024
Dist Fedora Esm H88
Fedora 39 has issued a critical security advisory addressing vulnerabilities in the rust-tower crate, urging users to update promptly to prevent remote exploitation risks
Update the hyper-rustls crate to version 0.27.3

Summary

Tower is a library of modular and reusable components for building

robust clients and servers.

Update Information:

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3. Update the tower crate to version 0.5.1 and add a compat package for version 0.4. Update the tower-http crate to version 0.6.1 and add a compat package for version 0.5.

Change Log

* Tue Oct 8 2024 Fabio Valentini - 0.5.1-1 - Update to version 0.5.1; Fixes RHBZ#2304674 * Sat Jul 20 2024 Fedora Release Engineering - 0.4.13-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Sat Jan 27 2024 Fedora Release Engineering - 0.4.13-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

References


[ 1 ] Bug #2316020 - CVE-2024-47609 rust-tonic: Remotely exploitable DoS in Tonic `<=v0.12.2` [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2316020

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ff98facbc6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rust-tower
Product: Fedora 39
Version: 0.5.1
Release: 1.fc39
Summary: Modular and reusable components for building robust clients and servers

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here