Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 41: Varnish Critical Fix for CVE-2025-47905 Client-Side Desync

fedora
Calendar Grey August 9, 2025
Dist Fedora Esm H88
Patch release for Varnish Cache fixes server-side timing issue in Fedora 41, boosting overall security measures.
Security: This update includes fixes for CVE-2025-47905 aka VSV00016: A client- side desync vulnerability can be triggered in Varnish Cache

Summary

This is Varnish Cache, a high-performance HTTP accelerator.

Varnish Cache stores web pages in memory so web servers don\u2019t have to

create the same web page over and over again. Varnish Cache serves

pages much faster than any application server; giving the website a

significant speed up.

Documentation wiki and additional information about Varnish Cache is

available on: https://vinyl-cache.org/

Update Information:

Security: This update includes fixes for CVE-2025-47905 aka VSV00016: A client- side desync vulnerability can be triggered in Varnish Cache. This vulnerability can be triggered under specific circumstances involving malformed HTTP/1 chunked requests.

Change Log

* Thu Jul 31 2025 Ingvar Hagelund - 7.5.0-4 - Security: Added patch for VSV00016 AKA CVE-2025-47905

References


[ 1 ] Bug #2369404 - CVE-2025-47905 varnish: request smuggling attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369404

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f7e5d2e40f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: varnish
Product: Fedora 41
Version: 7.5.0
Release: 4.fc41
Summary: High-performance HTTP accelerator

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here