Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 41: rust-maxminddb CVE-2025-53605 Uncontrolled Recursion Fix

fedora
Calendar Grey October 9, 2025
Dist Fedora Esm H88
Enhance Fedora 41 with updated rust-maxminddb preventing recursion risk; apply the latest patches now.
Update mirrorlist-server to version 3.0.8

Summary

Library for reading MaxMind DB format used by GeoIP2 and GeoLite2.

Update Information:

Update mirrorlist-server to version 3.0.8. Update the maxminddb crate to version 0.26.0. Update the prometheus crate to version 0.14.0. Update the protobuf and protobuf-codegen crates to version 3.7.2. Initial packaging of the protobuf-parse and protobuf-support crates. This includes fixes for CVE-2025-53605 (Uncontrolled Recursion Vulnerability in the protobuf crate).

Change Log

* Tue Sep 30 2025 Fabio Valentini - 0.26.0-1 - Update to version 0.26.0; Fixes RHBZ#2257537 * Fri Jul 25 2025 Fedora Release Engineering - 0.23.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Sun Jan 19 2025 Fedora Release Engineering - 0.23.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild

References


[ 1 ] Bug #2376749 - CVE-2025-53605 mirrorlist-server: Protobuf: Uncontrolled Recursion Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2376749

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2503abb88f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: rust-maxminddb
Product: Fedora 41
Version: 0.26.0
Release: 1.fc41
Summary: Library for reading MaxMind DB format used by GeoIP2 and GeoLite2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here