Patch to fix CVE-2024-31031. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-75863445ff 2024-05-03 01:40:26.180521 -------------------------------------------------------------------------------- Name : libcoap Product : Fedora 40 Version : 4.3.4a Release : 2.fc40 URL : https://libcoap.net/ Summary : C library implementation of CoAP Description : The Constrained Application Protocol (CoAP) is a specialized web transfer protocol for use with constrained nodes and constrained networks in the Internet of Things. The protocol is designed for machine-to-machine (M2M) applications such as smart energy and building automation. libcoap implements a lightweight application-protocol for devices with constrained resources such as computing power, RF range, memory, bandwidth, or network packet sizes. This protocol, CoAP, was standardized in the IETF working group "CoRE" as RFC 7252. -------------------------------------------------------------------------------- Update Information: Patch to fix CVE-2024-31031 -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 24 2024 Peter Robinson - 4.3.4a-2 - Patch to fix CVE-2024-31031 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2275804 - CVE-2024-31031 libcoap: unsigned integer overflow vulnerability in coap_pdu.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2275804 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-75863445ff' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-8b0938312e 2023-04-29 05:12:00.194966 --------------------------------------------------------------------------------Name : libsignal-protocol-c Product : Fedora 36 Version : 2.3.3 Release : 7.fc36 URL : https://github.com/signalapp/libsignal-protocol-c Summary : Signal Protocol C library Description : This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging environments. --------------------------------------------------------------------------------Update Information: Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217 https://github.com/protobuf-c/protobuf-c/issues/499 https://github.com/protobuf-c/protobuf-c/pull/513 https://github.com/protobuf-c/protobuf-c/releases/tag/v1.4.1 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 19 2023 Randy Barlow - 2.3.3-7 - Fix CVE-2022-48468: unsigned integer overflow (#2186673). --------------------------------------------------------------------------------References: [ 1 ] Bug #2186674 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2186674 [ 2 ] Bug #2186675 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2186675 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-8b0938312e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-6cfe134db6 2023-04-29 04:41:45.954640 --------------------------------------------------------------------------------Name : libsignal-protocol-c Product : Fedora 37 Version : 2.3.3 Release : 8.fc37 URL : https://github.com/signalapp/libsignal-protocol-c Summary : Signal Protocol C library Description : This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging environments. --------------------------------------------------------------------------------Update Information: Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217 https://github.com/protobuf-c/protobuf-c/issues/499 https://github.com/protobuf-c/protobuf-c/pull/513 https://github.com/protobuf-c/protobuf-c/releases/tag/v1.4.1 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 19 2023 Randy Barlow - 2.3.3-8 - Fix CVE-2022-48468: unsigned integer overflow (#2186673). --------------------------------------------------------------------------------References: [ 1 ] Bug #2186674 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2186674 [ 2 ] Bug #2186675 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2186675 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6cfe134db6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-4e094d5297 2023-04-29 02:52:14.059040 --------------------------------------------------------------------------------Name : libsignal-protocol-c Product : Fedora 38 Version : 2.3.3 Release : 9.fc38 URL : https://github.com/signalapp/libsignal-protocol-c Summary : Signal Protocol C library Description : This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging environments. --------------------------------------------------------------------------------Update Information: Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217 https://github.com/protobuf-c/protobuf-c/issues/499 https://github.com/protobuf-c/protobuf-c/pull/513 https://github.com/protobuf-c/protobuf-c/releases/tag/v1.4.1 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 19 2023 Randy Barlow - 2.3.3-9 - Fix CVE-2022-48468: unsigned integer overflow (#2186673). --------------------------------------------------------------------------------References: [ 1 ] Bug #2186674 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2186674 [ 2 ] Bug #2186675 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2186675 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-4e094d5297' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.