Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 41: fastd Security Fix for LOW Severity UDP Amplification

fedora
Calendar Grey February 4, 2025
Dist Fedora Esm H88
Debian releases patches for systemd enhancing defense mechanisms against minor escalation vulnerabilities and addressing various bugs.
This release contains a number of small improvements and bugfixes, including mitigations for the LOW severity vulnerability CVE-2025-24356

Summary

fastd is a secure tunneling daemon with some unique features:

- Very small binary (about 100KB on OpenWRT in the default configuration,

including all dependencies besides libc)

- Exchangable crypto methods

- Transport over UDP for simple usage behind NAT

- Can run in 1:1 and 1:n scenarios

- There are no server and client roles defined by the protocol, this is just

defined by the usage.

- Only one instance of the daemon is needed on each host to create a full mesh

If no full mesh is established, a routing protocol is necessary to enable

hosts that are not connected directly to reach each other

Update Information:

This release contains a number of small improvements and bugfixes, including mitigations for the LOW severity vulnerability CVE-2025-24356. Bugfixes Add mitigations for fast-reconnect amplification attacks When receiving a data packet from an unknown IP address/port combination, fastd will assume that one of its connected peers has moved to a new address (for example due to internet lines with dynamic IP, or roaming between WWAN and a local internet connection) and initiate a reconnect by sending a handshake packet. This “fast reconnect” avoids having to wait for a session timeout (up to ~90s) until a new connection is established. Even a 1-byte UDP packet just containing the fastd packet type header can trigger a much larger handshake packet (~150 bytes of UDP payload). With fastd v22, this number is doubled, because two handshakes are sent (one in a pre-v22-compatible format and one in a new L2TP-style format). Including IPv4 and UDP headers, the resulting amplification ...

Read the Full Advisory

Change Log

* Sun Jan 26 2025 Felix Kaechele - 23-1 - update to 23 * Thu Jan 16 2025 Fedora Release Engineering - 22-17 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild

References


[ 1 ] Bug #2342133 - fastd-23 is available https://bugzilla.redhat.com/show_bug.cgi?id=2342133 [ 2 ] Bug #2342338 - CVE-2025-24356 fastd: UDP traffic amplification via fastd's fast reconnect feature [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2342338

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b895b18cfe' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
low
Lowest
Low
Medium
High
Critical

Name: fastd
Product: Fedora 41
Version: 23
Release: 1.fc41
Summary: Fast and secure tunneling daemon

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here