Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 41: FEDORA-2024-4cadba7a29 critical: matrix-synapse memory leak

fedora
Calendar Grey December 13, 2024
Dist Fedora Esm H88
Security notice for Fedora 41 enhancements of matrix-synapse tackling various concerns, encompassing memory vulnerabilities.
CVE-2024-52805, CVE-2024-52815, CVE-2024-53863, CVE-2024-53867 Backport fixes from v1.120.1

Summary

Matrix is an ambitious new ecosystem for open federated Instant Messaging and

VoIP. Synapse is a reference "homeserver" implementation of Matrix from the

core development team at matrix.org, written in Python/Twisted. It is intended

to showcase the concept of Matrix and let folks see the spec in the context of

a coded base and let you run your own homeserver and generally help bootstrap

the ecosystem.

Update Information:

CVE-2024-52805, CVE-2024-52815, CVE-2024-53863, CVE-2024-53867 Backport fixes from v1.120.1

Change Log

* Tue Dec 3 2024 Kai A. Hiller - 1.118.0-3 - CVE-2024-52805, CVE-2024-52815, CVE-2024-53863, CVE-2024-53867 * Tue Dec 3 2024 Kai A. Hiller - 1.118.0-2 - Backport fixes from v1.120.1

References


[ 1 ] Bug #2330235 - CVE-2024-52805 matrix-synapse: Synapse allows unsupported content types to lead to memory exhaustion [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2330235 [ 2 ] Bug #2330236 - CVE-2024-53867 matrix-synapse: Synapse Matrix has a partial room state leak via Sliding Sync [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2330236 [ 3 ] Bug #2330238 - CVE-2024-52815 matrix-synapse: A malformed invite can break the invitee's `/sync` [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2330238 [ 4 ] Bug #2330240 - CVE-2024-53863 matrix-synapse: Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2330240

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4cadba7a29' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: matrix-synapse
Product: Fedora 41
Version: 1.118.0
Release: 3.fc41
Summary: A Matrix reference homeserver written in Python using Twisted

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here