Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 40: 2024-619ac47ce9 Critical: python-cbor2 Buffer Overflow

fedora
Calendar Grey April 19, 2024
Dist Fedora Esm H88
Keep informed about the recent Fedora 40 python-cbor2 notice concerning a buffer overflow vulnerability and additional updates.
Update to latest upstream release (closes rhbz#2261550, closes rhbz#2245361)

Summary

This library provides encoding and decoding for the Concise Binary Object

Representation (CBOR) (RFC 7049) serialization format.

Update Information:

Update to latest upstream release (closes rhbz#2261550, closes rhbz#2245361)

Change Log

* Mon Apr 8 2024 Fabian Affolter - 5.6.2-1 - Update to latest upstream release (closes rhbz#2261550, closes rhbz#2245361) - Fixes CVE-2024-26134 (closes rhbz#2265036, closes rhbz#bug 2265035) * Sat Feb 3 2024 Fabian Affolter - 5.6.1-1 - Update to latest upstream release 5.6.1 (closes rhbz#2245361) * Fri Jan 26 2024 Fedora Release Engineering - 5.1.2-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Mon Jan 22 2024 Fedora Release Engineering - 5.1.2-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

References


[ 1 ] Bug #2245361 - python-cbor2-5.6.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2245361 [ 2 ] Bug #2261550 - python-cbor2: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261550 [ 3 ] Bug #2265036 - CVE-2024-26134 python-cbor2: cbor2: Potential buffer overflow in CBOR2 decoder [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2265036

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-619ac47ce9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-cbor2
Product: Fedora 40
Version: 5.6.2
Release: 1.fc40
Summary: Python CBOR (de)serializer with extensive tag support

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here