Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 41: FEDORA-2025-a13867ecbc critical: rust-openssl-sys use-after-free

fedora
Calendar Grey April 17, 2025
Dist Fedora Esm H88
Upgrade to rust-openssl-sys 0.9.107 rectifying a significant use-after-free vulnerability in Fedora 41. Discover more about this resolution.
Update the openssl crate to version 0.10.72

Summary

FFI bindings to OpenSSL.

Update Information:

Update the openssl crate to version 0.10.72. Update the openssl-sys crate to version 0.9.107. This update addresses CVE-2025-3416 / RUSTSEC-2025-0022 (a possible use-after- free issue in two public functions). A survey of dependent packages in Fedora shows that none of them use the affected API, or do not use them in a way that triggers this issue.

Change Log

* Tue Apr 8 2025 Fabio Valentini - 0.9.107-1 - Update to version 0.9.107; Fixes RHBZ#2357490

References

Fedora Update Notification FEDORA-2025-a13867ecbc 2025-04-17 19:46:50.126435+00:00 Name : rust-openssl-sys Product : Fedora 41 Version : 0.9.107 Release : 1.fc41 URL : https://crates.io/crates/openssl-sys Summary : FFI bindings to OpenSSL Description : FFI bindings to OpenSSL.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a13867ecbc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rust-openssl-sys
Product: Fedora 41
Version: 0.9.107
Release: 1.fc41
Summary: FFI bindings to OpenSSL

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here