[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4658-1] librabbitmq security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4658-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                           Chris Lamb
June 30, 2026                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : librabbitmq
Version        : 0.10.0-1+deb11u2 0.11.0-1+deb12u2
CVE ID         : CVE-2026-44235 CVE-2026-44236

Two issues were discovered in librabbitmq, a C-language client
library used to communicate with RabbitMQ servers using the Advanced
Message Queuing Protocol (AMQP).

CVE-2026-44235

    A size_t underflow in AMQP frame length computation could have
    led to an out-of-bounds read.

CVE-2026-44236

    A heap buffer overflow in AMQP login handshake via undersized
    connection.tune.frame_max.

For Debian 11 bullseye, these problems have been fixed in version
0.10.0-1+deb11u2.

For Debian 12 bookworm, these problems have been fixed in version
0.11.0-1+deb12u2.

We recommend that you upgrade your librabbitmq packages.

For the detailed security status of librabbitmq please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/librabbitmq

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmpEANQACgkQHpU+J9Qx
HlgeEhAAnvCzO/ARkLHoAVBIain9iF5ipwQS/VYv2Hys3spROcApybNP2/mwPJh5
4xLLox7gsDGFGvilfJRB9iasjyzuI6/uarzZirXj5/tPL8u710nXfcJYz3gsx9Wj
vXHd1tUZsSGLBV0H/Jn27uXVtVXjcXqZKyBihZwRgVghbu93nOSp6InypOZK+PEU
BffOBAJRKpW0SXkiPVBVcOT/FBd31l4gXDsL+NRq2g4QwP2qmZrh//9A+HiyfpD9
5qZasz1ZtkATkNfQDhxfLQx3fnO4wyxjanY95D6xKaJpL3FRA4FncXa7StnZTbDM
EyBe2ogE9Cu/VrCb15eLLvDVs/qqMBvLlTW3+a+PPAlC0KIWAaQE4T8J049Xw6Rb
0/qTHEBQLfftsyqwmO49iDIp6tZ1TGrEcbw+6cVQpU9G2OE7sW4bhpNuNOruhYfX
jVoKBQTWhxynssjovGVT+RDPYSFhO9kiZFiGYdrINKZdtSL1UQmozhed+Qxzcu5F
EUedOwRGfDDNav45ib50aaOWhyhVq+JSkKG5Q9njVHseCcXT9LrTnWeVdwH7QK2c
e3IuG1koc5yQ/8y6LB/Zh5fcpwF1+OsYPH3mcmrNWCP6UVn5chrVUrIIeqPwM00Z
6iEWVyHmxuOYVzMjoXkhO+wSWkvzQENwibJNevY5ixkVHg2s95k=
=7KNs
-----END PGP SIGNATURE-----


Reply to: