[SECURITY] [DLA 4658-1] librabbitmq security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4658-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Chris Lamb
June 30, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : librabbitmq
Version : 0.10.0-1+deb11u2 0.11.0-1+deb12u2
CVE ID : CVE-2026-44235 CVE-2026-44236
Two issues were discovered in librabbitmq, a C-language client
library used to communicate with RabbitMQ servers using the Advanced
Message Queuing Protocol (AMQP).
CVE-2026-44235
A size_t underflow in AMQP frame length computation could have
led to an out-of-bounds read.
CVE-2026-44236
A heap buffer overflow in AMQP login handshake via undersized
connection.tune.frame_max.
For Debian 11 bullseye, these problems have been fixed in version
0.10.0-1+deb11u2.
For Debian 12 bookworm, these problems have been fixed in version
0.11.0-1+deb12u2.
We recommend that you upgrade your librabbitmq packages.
For the detailed security status of librabbitmq please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/librabbitmq
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmpEANQACgkQHpU+J9Qx
HlgeEhAAnvCzO/ARkLHoAVBIain9iF5ipwQS/VYv2Hys3spROcApybNP2/mwPJh5
4xLLox7gsDGFGvilfJRB9iasjyzuI6/uarzZirXj5/tPL8u710nXfcJYz3gsx9Wj
vXHd1tUZsSGLBV0H/Jn27uXVtVXjcXqZKyBihZwRgVghbu93nOSp6InypOZK+PEU
BffOBAJRKpW0SXkiPVBVcOT/FBd31l4gXDsL+NRq2g4QwP2qmZrh//9A+HiyfpD9
5qZasz1ZtkATkNfQDhxfLQx3fnO4wyxjanY95D6xKaJpL3FRA4FncXa7StnZTbDM
EyBe2ogE9Cu/VrCb15eLLvDVs/qqMBvLlTW3+a+PPAlC0KIWAaQE4T8J049Xw6Rb
0/qTHEBQLfftsyqwmO49iDIp6tZ1TGrEcbw+6cVQpU9G2OE7sW4bhpNuNOruhYfX
jVoKBQTWhxynssjovGVT+RDPYSFhO9kiZFiGYdrINKZdtSL1UQmozhed+Qxzcu5F
EUedOwRGfDDNav45ib50aaOWhyhVq+JSkKG5Q9njVHseCcXT9LrTnWeVdwH7QK2c
e3IuG1koc5yQ/8y6LB/Zh5fcpwF1+OsYPH3mcmrNWCP6UVn5chrVUrIIeqPwM00Z
6iEWVyHmxuOYVzMjoXkhO+wSWkvzQENwibJNevY5ixkVHg2s95k=
=7KNs
-----END PGP SIGNATURE-----
Reply to: