Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Warning: Undefined array key "Description" in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 220

Fedora 43: Important Fix for Rust Monitord Exporter Protobuf Recursion

fedora
Calendar Grey October 14, 2025
Dist Fedora Esm H88
Critical update for Fedora 43's rust-monitord-exporter addressing CVE-2025-53605 uncontrolled recursion issue.
Update mirrorlist-server to version 3.0.8

Summary

monitord-exporter is a Prometheus exporter using monitord to export statistic to Prometheus collectors.

Update Information:

Update mirrorlist-server to version 3.0.8. Update the maxminddb crate to version 0.26.0. Update the prometheus crate to version 0.14.0. Update the protobuf and protobuf-codegen crates to version 3.7.2. Initial packaging of the protobuf-parse and protobuf-support crates. This includes fixes for CVE-2025-53605 (Uncontrolled Recursion Vulnerability in the protobuf crate).

Change Log

* Mon Oct 6 2025 Fabio Valentini - 0.4.1-6 - Add missing type annotation for prometheus 0.14 compatibility

References


[ 1 ] Bug #2376751 - CVE-2025-53605 mirrorlist-server: Protobuf: Uncontrolled Recursion Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2376751 [ 2 ] Bug #2401160 - F43FailsToInstall: rust-prometheus+protobuf-codegen-pure-devel https://bugzilla.redhat.com/show_bug.cgi?id=2401160

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9e77f6ddcb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rust-monitord-exporter
Product: Fedora 43
Version: 0.4.1
Release: 6.fc43
Summary: Let Prometheus know how happy your systemd is

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here