Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Fedora 42: 2025-c263d3ebd9 critical: rust-openssl use-after-free

fedora
Calendar Grey April 17, 2025
Dist Fedora Esm H88
Fedora 42 users must update their systems to address a critical use-after-free vulnerability in the rust-openssl library to maintain security
Update the openssl crate to version 0.10.72

Summary

OpenSSL bindings.

Update Information:

Update the openssl crate to version 0.10.72. Update the openssl-sys crate to version 0.9.107. This update addresses CVE-2025-3416 / RUSTSEC-2025-0022 (a possible use-after- free issue in two public functions). A survey of dependent packages in Fedora shows that none of them use the affected API, or do not use them in a way that triggers this issue.

Change Log

* Tue Apr 8 2025 Fabio Valentini - 0.10.72-1 - Update to version 0.10.72; Fixes RHBZ#2357489

References

Fedora Update Notification FEDORA-2025-c263d3ebd9 2025-04-17 18:59:47.310294+00:00 Name : rust-openssl Product : Fedora 42 Version : 0.10.72 Release : 1.fc42 URL : https://crates.io/crates/openssl Summary : OpenSSL bindings Description : OpenSSL bindings.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c263d3ebd9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rust-openssl
Product: Fedora 42
Version: 0.10.72
Release: 1.fc42
Summary: OpenSSL bindings

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here