Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 40 fastd 2025-29fc4fefd5 Low: UDP amplification attack

fedora
Calendar Grey February 5, 2025
Dist Fedora Esm H88
Fedora 40 introduces updates for Fastd, mitigating minor amplification vulnerabilities; accompanied by security advisory and crucial bug fixes.
This release contains a number of small improvements and bugfixes, including mitigations for the LOW severity vulnerability CVE-2025-24356

Summary

fastd is a secure tunneling daemon with some unique features:

- Very small binary (about 100KB on OpenWRT in the default configuration,

including all dependencies besides libc)

- Exchangable crypto methods

- Transport over UDP for simple usage behind NAT

- Can run in 1:1 and 1:n scenarios

- There are no server and client roles defined by the protocol, this is just

defined by the usage.

- Only one instance of the daemon is needed on each host to create a full mesh

If no full mesh is established, a routing protocol is necessary to enable

hosts that are not connected directly to reach each other

Update Information:

This release contains a number of small improvements and bugfixes, including mitigations for the LOW severity vulnerability CVE-2025-24356. Bugfixes Add mitigations for fast-reconnect amplification attacks When receiving a data packet from an unknown IP address/port combination, fastd will assume that one of its connected peers has moved to a new address (for example due to internet lines with dynamic IP, or roaming between WWAN and a local internet connection) and initiate a reconnect by sending a handshake packet. This “fast reconnect” avoids having to wait for a session timeout (up to ~90s) until a new connection is established. Even a 1-byte UDP packet just containing the fastd packet type header can trigger a much larger handshake packet (~150 bytes of UDP payload). With fastd v22, this number is doubled, because two handshakes are sent (one in a pre-v22-compatible format and one in a new L2TP-style format). Including IPv4 and UDP headers, the resulting amplification ...

Read the Full Advisory

Change Log

* Sun Jan 26 2025 Felix Kaechele - 23-1 - update to 23 * Thu Jan 16 2025 Fedora Release Engineering - 22-17 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Jul 17 2024 Fedora Release Engineering - 22-16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild

References


[ 1 ] Bug #2342133 - fastd-23 is available https://bugzilla.redhat.com/show_bug.cgi?id=2342133 [ 2 ] Bug #2342337 - CVE-2025-24356 fastd: UDP traffic amplification via fastd's fast reconnect feature [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2342337

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-29fc4fefd5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
low
Lowest
Low
Medium
High
Critical

Name: fastd
Product: Fedora 40
Version: 23
Release: 1.fc40
Summary: Fast and secure tunneling daemon

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here