Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 40: FEDORA-2025-3f77ed652b critical: UPX heap overflow

fedora
Calendar Grey April 6, 2025
Dist Fedora Esm H88
Ubuntu 22.04 upgrade fixes severe buffer overflow in UPX version 5.0.0. Utilize apt for better system stability and security.
5.0.0

Summary

UPX is a free, portable, extendable, high-performance executable

packer for several different executable formats. It achieves an

excellent compression ratio and offers very fast decompression. Your

executables suffer no memory overhead or other drawbacks.

Update Information:

5.0.0

Change Log

* Thu Feb 20 2025 Gwyn Ciesla - 5.0.0-1 - 5.0.0 * Sun Jan 19 2025 Fedora Release Engineering - 4.2.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Dec 18 2024 Gwyn Ciesla - 4.2.4-3 - Provide bundled lzma-sdk * Sat Jul 20 2024 Fedora Release Engineering - 4.2.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild

References


[ 1 ] Bug #2355649 - CVE-2025-2849 upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2355649 [ 2 ] Bug #2355650 - CVE-2025-2849 upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2355650 [ 3 ] Bug #2355651 - CVE-2025-2849 upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2355651

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3f77ed652b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: upx
Product: Fedora 40
Version: 5.0.0
Release: 1.fc40
Summary: Ultimate Packer for eXecutables

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here