Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 42: bpfman Security Update CVE-2025-0977 Use-After-Free

fedora
Calendar Grey November 9, 2025
Dist Fedora Esm H88
Fix for CVE-2025-0977 (use-after-free) in bpfman on Fedora 42, updating openssl crate to enhance security.
This update fixes CVE-2025-0977 (RUSTSEC-2025-0004), a use-after-free vulnerability in the Rust openssl crate's ssl::select_next_proto function

Summary

bpfman operates as an eBPF manager, focusing on simplifying the deployment and

administration of eBPF programs.

Update Information:

This update fixes CVE-2025-0977 (RUSTSEC-2025-0004), a use-after-free vulnerability in the Rust openssl crate's ssl::select_next_proto function. The openssl crate has been updated from version 0.10.67 to 0.10.70 in the vendored dependencies.

Change Log

* Fri Oct 31 2025 Daniel Mellado - 0.5.4-3 - Fix CVE-2025-0977: Update openssl to 0.10.70 - closes rhbz#2344554 * Wed Jul 23 2025 Fedora Release Engineering - 0.5.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Mon Jun 23 2025 Daniel Mellado - 0.5.4-1 - Add patch for Cargo.lock - closes rhbz2370581 * Sat Jun 7 2025 Daniel Mellado - 0.5.6-1 - Update to version 0.5.6 * Thu Jan 16 2025 Fedora Release Engineering - 0.5.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Dec 18 2024 Daniel Mellado - 0.5.4-4 - Correct sources vendor file * Wed Dec 18 2024 Daniel Mellado - 0.5.4-3 - Remove forbidden RTLO characters in vendor/idna-5.0 tests

References


[ 1 ] Bug #2344554 - bpfman: openssl: CVE-2025-0977 / RUSTSEC-2025-0004: ssl::select_next_proto use after free https://bugzilla.redhat.com/show_bug.cgi?id=2344554

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-0753bddd6c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: bpfman
Product: Fedora 42
Version: 0.5.4
Release: 3.fc42
Summary: EBPF Program Manager

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here