Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 39 Syncthing 1.27.3 Critical Update Against Memory Attack

fedora
Calendar Grey February 21, 2024
Dist Fedora Esm H88
Fedora 39 has updated Syncthing to version 1.27.3, addressing the CVE-2023-49295 security issue while enhancing file management and monitoring capabilities.
Update to version 1.27.3

Summary

Syncthing replaces other file synchronization services with something

open, trustworthy and decentralized. Your data is your data alone and

you deserve to choose where it is stored, if it is shared with some

third party and how it's transmitted over the Internet. Using syncthing,

that control is returned to you.

This package contains the syncthing client binary and systemd services.

Update Information:

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

Change Log

* Mon Feb 12 2024 Fabio Valentini - 1.27.3-1 - Update to version 1.27.3; Fixes RHBZ#2263121 * Sun Feb 11 2024 Maxwell G - 1.27.2-3 - Rebuild for golang 1.22.0 * Sat Jan 27 2024 Fedora Release Engineering - 1.27.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

References


[ 1 ] Bug #2257833 - CVE-2023-49295 syncthing: quic-go: memory exhaustion attack against QUIC's path validation mechanism [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257833

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c46536abe6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: syncthing
Product: Fedora 39
Version: 1.27.3
Release: 1.fc39
Summary: Continuous File Synchronization

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here