Several security issues were fixed in Raptor.. ========================================================================== Ubuntu Security Notice USN-7869-1 November 10, 2025 raptor2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Raptor. Software Description: - raptor2: RDF syntax library Details: Hanno Böck discovered that Raptor incorrectly handled memory operations when processing certain input files. An attacker could possibly use this issue to cause Raptor to crash, resulting in a denial of service. (CVE-2020-25713) Pedro Ribeiro discovered that Raptor incorrectly handled parsing certain tuples. An attacker could possibly use this issue to cause Raptor to crash, resulting in a denial of service. (CVE-2024-57822) Pedro Ribeiro discovered that Raptor incorrectly handled parsing certain turtles. An attacker could use this issue to cause Raptor to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2024-57823) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libraptor2-0 2.0.14-1ubuntu0.18.04.1+esm1 Available with Ubuntu Pro raptor2-utils 2.0.14-1ubuntu0.18.04.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libraptor2-0 2.0.14-1ubuntu0.16.04.1+esm1 Available with Ubuntu Pro raptor2-utils 2.0.14-1ubuntu0.16.04.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7869-1 CVE-2020-25713, CVE-2024-57822, CVE-2024-57823 . Significant security issues fixed in Raptoraffecting Ubuntu 16.04 and 18.04. Immediate update required for protection.. Raptor2 Update, Ubuntu Security, Memory Handling Issues, Denial of Service, Security Fix. . Severity: Critical. LinuxSecurity.com Team
Important: raptor2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:0314", "synopsis": "Important: raptor2 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for raptor2.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Raptor is the RDF Parser Toolkit for Redland that provides a set of standalone RDF parsers, generating triples from RDF/XML or N-Triples. \n\nSecurity Fix(es):\n\n* raptor: integer underflow when normalizing a URI with the turtle parser (CVE-2024-57823)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2336921", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2336921", "description": ""}], "cves": [{"name": "CVE-2024-57823", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-57823", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2025-01-17T16:13:58.660055Z", "rpms": {"Rocky Linux 8": {"nvras": ["raptor2-0:2.0.15-17.el8_10.aarch64.rpm", "raptor2-0:2.0.15-17.el8_10.i686.rpm", "raptor2-0:2.0.15-17.el8_10.src.rpm", "raptor2-0:2.0.15-17.el8_10.x86_64.rpm", "raptor2-debuginfo-0:2.0.15-17.el8_10.aarch64.rpm", "raptor2-debuginfo-0:2.0.15-17.el8_10.i686.rpm", "raptor2-debuginfo-0:2.0.15-17.el8_10.x86_64.rpm", "raptor2-debugsource-0:2.0.15-17.el8_10.aarch64.rpm", "raptor2-debugsource-0:2.0.15-17.el8_10.i686.rpm", "raptor2-debugsource-0:2.0.15-17.el8_10.x86_64.rpm", "raptor2-devel-0:2.0.15-17.el8_10.aarch64.rpm", "raptor2-devel-0:2.0.15-17.el8_10.i686.rpm", "raptor2-devel-0:2.0.15-17.el8_10.x86_64.rpm"]}}, "rebootSuggested": false,"buildReferences": []}. AlmaLinux has unveiled a crucial update addressing severe raptor2 vulnerabilities related to URI normalization. Please ensure you update immediately.. raptor2 security update, Rocky Linux advisory, integer underflow fix, RDF Parser Toolkit. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0314 http://linux.oracle.com/errata/ELSA-2025-0314.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: raptor2-2.0.15-17.el8_10.i686.rpm raptor2-2.0.15-17.el8_10.x86_64.rpm raptor2-devel-2.0.15-17.el8_10.i686.rpm raptor2-devel-2.0.15-17.el8_10.x86_64.rpm aarch64: raptor2-2.0.15-17.el8_10.aarch64.rpm raptor2-devel-2.0.15-17.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//raptor2-2.0.15-17.el8_10.src.rpm Related CVEs: CVE-2024-57823 Description of changes: [2.0.15-17] - Resolves: CVE-2024-57823 integer underflow when normalizing a URI with the turtle parser _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0312 http://linux.oracle.com/errata/ELSA-2025-0312.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: raptor2-2.0.15-32.el9_5.i686.rpm raptor2-2.0.15-32.el9_5.x86_64.rpm raptor2-devel-2.0.15-32.el9_5.i686.rpm raptor2-devel-2.0.15-32.el9_5.x86_64.rpm aarch64: raptor2-2.0.15-32.el9_5.aarch64.rpm raptor2-devel-2.0.15-32.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//raptor2-2.0.15-32.el9_5.src.rpm Related CVEs: CVE-2024-57823 Description of changes: [2.0.15-32] - Bump NVR [2.0.15-31] - Resolves: CVE-2024-57823 integer underflow when normalizing a URI with the turtle parser _______________________________________________ El-errata mailing list
An issue has been found in raptor2, a Raptor RDF parser and serializer library. Malformed input file can lead to a segfault. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2846-1
An update for raptor2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: raptor2 security and bug fix update Advisory ID: RHSA-2021:1842-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:1842 Issue date: 2021-05-18 CVE Names: CVE-2017-18926 CVE-2020-25713 ==================================================================== 1. Summary: An update for raptor2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream (v. 8) - ppc64le, x86_64 3. Description: Raptor is the RDF Parser Toolkit for Redland that provides a set of standalone RDF parsers, generating triples from RDF/XML or N-Triples. Security Fix(es): * raptor: heap-based buffer overflows due to an error in calculating the maximum nspace declarations for the XML writer (CVE-2017-18926) * raptor2: malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common (CVE-2020-25713) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailedinformation on changes in this release, see the Red Hat Enterprise Linux 8.4 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1896120 - CVE-2017-18926 raptor: heap-based buffer overflows due to an error in calculating the maximum nspace declarations for the XML writer 1900685 - CVE-2020-25713 raptor2: malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: raptor2-2.0.15-16.el8.src.rpm ppc64le: raptor2-2.0.15-16.el8.ppc64le.rpm raptor2-debuginfo-2.0.15-16.el8.ppc64le.rpm raptor2-debugsource-2.0.15-16.el8.ppc64le.rpm x86_64: raptor2-2.0.15-16.el8.i686.rpm raptor2-2.0.15-16.el8.x86_64.rpm raptor2-debuginfo-2.0.15-16.el8.i686.rpm raptor2-debuginfo-2.0.15-16.el8.x86_64.rpm raptor2-debugsource-2.0.15-16.el8.i686.rpm raptor2-debugsource-2.0.15-16.el8.x86_64.rpm Red Hat CodeReady Linux Builder (v. 8): Source: raptor2-2.0.15-16.el8.src.rpm aarch64: raptor2-2.0.15-16.el8.aarch64.rpm raptor2-debuginfo-2.0.15-16.el8.aarch64.rpm raptor2-debugsource-2.0.15-16.el8.aarch64.rpm raptor2-devel-2.0.15-16.el8.aarch64.rpm ppc64le: raptor2-debuginfo-2.0.15-16.el8.ppc64le.rpm raptor2-debugsource-2.0.15-16.el8.ppc64le.rpm raptor2-devel-2.0.15-16.el8.ppc64le.rpm s390x: raptor2-2.0.15-16.el8.s390x.rpm raptor2-debuginfo-2.0.15-16.el8.s390x.rpm raptor2-debugsource-2.0.15-16.el8.s390x.rpm raptor2-devel-2.0.15-16.el8.s390x.rpm x86_64: raptor2-debuginfo-2.0.15-16.el8.i686.rpm raptor2-debuginfo-2.0.15-16.el8.x86_64.rpm raptor2-debugsource-2.0.15-16.el8.i686.rpm raptor2-debugsource-2.0.15-16.el8.x86_64.rpm raptor2-devel-2.0.15-16.el8.i686.rpm raptor2-devel-2.0.15-16.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature areavailable from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-18926 https://access.redhat.com/security/cve/CVE-2020-25713 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYKPu/tzjgjWX9erEAQgvsA/7BoaneBTEWXytptZMa7Nc5++hnDAF8wk+ YOrgBMDRfkR2aFp0nuLGXWMGLIQfU1dZxBSjjdXd5Uh3oFdkyYYs9cEzRQdWsi9C z3qwXBvGzqYSSnEObodQlyN3D2O0LIV2xC8+bJetridDJXvnCiB7DIYp7HOiRXDE LF4480Iv692fzqq0n+OPaoZ/fj9WmwFoWhe50qSQI+3gc2cstpicBKPROG7Qgttd riPHoG5UjKSmSyIZVrC81m6tBETABmaHC9HYaDb7sJlBMowR/1XS1jVAGefwV0ki iku8j1kmO+dwtma+e2L/r24RamN7oe8GWWnmIjOxeL9UbPJNS3YMnU0IEPYUm4fP O/ZiANmrMlQGbXZPbqY6V60Oe308QVg4Yew5afSP5pp6aW27xZbOuqDBbrmXOi/5 mxMCCWoSVLtZNRqClDmJMr/3YiDmLJtZOtpPDDuClpIkTAGckdFvsXi+LQQNb7k4 U6pZtk155KYLQE58WWrHO9E49366uFhT10dt5K6ssCeYFmQYuUblA2l616/nSVpt KOnQc7iWwmNK4pmmWyL5GpcNuRhM7kyAY4PosdOkMSVpXU8RdnFYcEzq9dpTc86o oJMRf0qTNTN0mQLM1IA2UXPLt30zZGAWsf/4vDWj+Cy3lGs5Jv1NiVLf2Oq0xsWG pfZ1aY8i7Lc=nlNa -----END PGP SIGNATURE----- -- RHSA-announce mailing list
A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common. (CVE-2020-25713) References: - https://bugs.mageia.org/show_bug.cgi?id=27605 . MGASA-2020-0431 - Updated raptor2 packages fix a security vulnerability Publication date: 21 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0431.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-25713 A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common. (CVE-2020-25713) References: - https://bugs.mageia.org/show_bug.cgi?id=27605 - https://bugs.librdf.org/mantis/view.php?id=650 - https://www.openwall.com/lists/oss-security/2020/11/13/1 - https://www.openwall.com/lists/oss-security/2020/11/16/1 - https://www.cve.org/CVERecord?id=CVE-2020-25713 SRPMS: - 7/core/raptor2-2.0.15-11.1.mga7 . Revised raptor2 distributions address a vulnerability in Mageia that arises from incorrect input processing, resulting in a segmentation fault.. Security Update,Mageia Advisory,Raptor2 Segfault,Input File Vulnerability. . LinuxSecurity.com Team
raptor2 could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4630-1 November 11, 2020 raptor2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: raptor2 could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - raptor2: RDF syntax library Details: Hanno Böck discovered that Raptor incorrectly handled certain memory operations. If a user were tricked into opening a specially crafted document in an application linked against Raptor, an attacker could cause the application to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: libraptor2-0 2.0.15-0ubuntu1.20.10.1 Ubuntu 20.04 LTS: libraptor2-0 2.0.15-0ubuntu1.20.04.1 Ubuntu 18.04 LTS: libraptor2-0 2.0.14-1ubuntu0.18.04.1 Ubuntu 16.04 LTS: libraptor2-0 2.0.14-1ubuntu0.16.04.1 After a standard system update you need to restart any applications which use Raptor, such as LibreOffice, to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4630-1 CVE-2017-18926 Package Information: https://launchpad.net/ubuntu/+source/raptor2/2.0.15-0ubuntu1.20.10.1 https://launchpad.net/ubuntu/+source/raptor2/2.0.15-0ubuntu1.20.04.1 https://launchpad.net/ubuntu/+source/raptor2/2.0.14-1ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/raptor2/2.0.14-1ubuntu0.16.04.1 . Raptor2 flaw impacts Ubuntu distributions; update released to avert software failure andpotential code exploitation.. Raptor2 Vulnerability, Ubuntu Security Notice, Denial of Service. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.