Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 40: 2025-472776e5dc critical: rust-openssl-sys use-after-free

fedora
Calendar Grey April 17, 2025
Dist Fedora Esm H88
Tackling the memory safety flaw in rust-openssl-sys, with essential patches released for Fedora 40.
Update the openssl crate to version 0.10.72

Summary

FFI bindings to OpenSSL.

Update Information:

Update the openssl crate to version 0.10.72. Update the openssl-sys crate to version 0.9.107. This update addresses CVE-2025-3416 / RUSTSEC-2025-0022 (a possible use-after- free issue in two public functions). A survey of dependent packages in Fedora shows that none of them use the affected API, or do not use them in a way that triggers this issue.

Change Log

* Tue Apr 8 2025 Fabio Valentini - 0.9.107-1 - Update to version 0.9.107; Fixes RHBZ#2357490

References

Fedora Update Notification FEDORA-2025-472776e5dc 2025-04-17 19:32:14.984584+00:00 Name : rust-openssl-sys Product : Fedora 40 Version : 0.9.107 Release : 1.fc40 URL : https://crates.io/crates/openssl-sys Summary : FFI bindings to OpenSSL Description : FFI bindings to OpenSSL.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-472776e5dc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rust-openssl-sys
Product: Fedora 40
Version: 0.9.107
Release: 1.fc40
Summary: FFI bindings to OpenSSL

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here