Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Critical Uncontrolled Recursion Vulnerability in Fedora 43: rust-maxminddb

fedora
Calendar Grey October 14, 2025
Dist Fedora Esm H88
Addressing a critical uncontrolled recursion issue in rust-maxminddb with necessary updates to related crates in Fedora 43.
Update mirrorlist-server to version 3.0.8

Summary

Library for reading MaxMind DB format used by GeoIP2 and GeoLite2.

Update Information:

Update mirrorlist-server to version 3.0.8. Update the maxminddb crate to version 0.26.0. Update the prometheus crate to version 0.14.0. Update the protobuf and protobuf-codegen crates to version 3.7.2. Initial packaging of the protobuf-parse and protobuf-support crates. This includes fixes for CVE-2025-53605 (Uncontrolled Recursion Vulnerability in the protobuf crate).

Change Log

* Tue Sep 30 2025 Fabio Valentini - 0.26.0-1 - Update to version 0.26.0; Fixes RHBZ#2257537

References


[ 1 ] Bug #2376751 - CVE-2025-53605 mirrorlist-server: Protobuf: Uncontrolled Recursion Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2376751 [ 2 ] Bug #2401160 - F43FailsToInstall: rust-prometheus+protobuf-codegen-pure-devel https://bugzilla.redhat.com/show_bug.cgi?id=2401160

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9e77f6ddcb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rust-maxminddb
Product: Fedora 43
Version: 0.26.0
Release: 1.fc43
Summary: Library for reading MaxMind DB format used by GeoIP2 and GeoLite2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here