Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Fedora 43: bpfman CVE-2025-0977 Use-After-Free Advisory Announcement

fedora
Calendar Grey November 9, 2025
Dist Fedora Esm H88
CVE-2025-0977 fixed in Fedora 43 for bpfman, addressing use-after-free vulnerability in Rust OpenSSL crate.
This update fixes CVE-2025-0977 (RUSTSEC-2025-0004), a use-after-free vulnerability in the Rust openssl crate's ssl::select_next_proto function

Summary

bpfman operates as an eBPF manager, focusing on simplifying the deployment and

administration of eBPF programs.

Update Information:

This update fixes CVE-2025-0977 (RUSTSEC-2025-0004), a use-after-free vulnerability in the Rust openssl crate's ssl::select_next_proto function. The openssl crate has been updated from version 0.10.67 to 0.10.70 in the vendored dependencies.

Change Log

* Fri Oct 31 2025 Daniel Mellado - 0.5.4-3 - Fix CVE-2025-0977: Update openssl to 0.10.70 - closes rhbz#2344554

References


[ 1 ] Bug #2344554 - bpfman: openssl: CVE-2025-0977 / RUSTSEC-2025-0004: ssl::select_next_proto use after free https://bugzilla.redhat.com/show_bug.cgi?id=2344554

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e67231423f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: bpfman
Product: Fedora 43
Version: 0.5.4
Release: 3.fc43
Summary: EBPF Program Manager

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here