Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 42: Varnish High CVE-2025-47905 Client-Side Desync Advisory

fedora
Calendar Grey August 8, 2025
Dist Fedora Esm H88
Mitigation for CVE-2025-47905 enhancing Varnish Cache's resilience to potential client-side desynchronization risks.
Security: This update includes fixes for CVE-2025-47905 aka VSV00016: A client- side desync vulnerability can be triggered in Varnish Cache

Summary

This is Varnish Cache, a high-performance HTTP accelerator.

Varnish Cache stores web pages in memory so web servers don\u2019t have to

create the same web page over and over again. Varnish Cache serves

pages much faster than any application server; giving the website a

significant speed up.

Documentation wiki and additional information about Varnish Cache is

available on: https://vinyl-cache.org/

Update Information:

Security: This update includes fixes for CVE-2025-47905 aka VSV00016: A client- side desync vulnerability can be triggered in Varnish Cache. This vulnerability can be triggered under specific circumstances involving malformed HTTP/1 chunked requests.

Change Log

* Wed Jul 30 2025 Ingvar Hagelund - 7.6.1-6 - Added security patch for VSV00016 aka CVE-2025-47905, rhbz#2369404

References


[ 1 ] Bug #2369404 - CVE-2025-47905 varnish: request smuggling attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369404

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-525d870026' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: varnish
Product: Fedora 42
Version: 7.6.1
Release: 6.fc42
Summary: High-performance HTTP accelerator

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here