Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 43: rclone 1.72.0 Critical CPU Memory Issues 2025-5e299f890a

fedora
Calendar Grey December 3, 2025
Dist Fedora Esm H88
Update to Fedora 43 rclone 1.72.0 addresses critical security issues related to cloud storage functionality.
Update to 1.72.0

Summary

"rsync for cloud storage" - Google Drive, S3, Dropbox, Backblaze B2, One Drive,

Swift, Hubic, Wasabi, Google Cloud Storage, Azure Blob, Azure Files, Yandex

Files.

Update Information:

Update to 1.72.0

Change Log

* Mon Nov 24 2025 Mikel Olasagasti Uranga - 1.72.0-1 - Update to 1.72.0 - Closes rhbz#2397899 * Fri Oct 10 2025 Alejandro Sez - 1.71.0-2 - rebuild

References


[ 1 ] Bug #2408342 - CVE-2025-58189 rclone: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408342 [ 2 ] Bug #2408741 - CVE-2025-61725 rclone: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408741 [ 3 ] Bug #2409815 - CVE-2025-61723 rclone: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409815 [ 4 ] Bug #2410765 - CVE-2025-58185 rclone: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410765 [ 5 ] Bug #2411661 - CVE-2025-58188 rclone: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411661

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5e299f890a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rclone
Product: Fedora 43
Version: 1.72.0
Release: 1.fc43
Summary: Rsync for cloud storage

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here