|
|
Log in / Subscribe / Register

Fedora alert FEDORA-2025-d408d76c4a (libcoap)

From:  updates--- via package-announce <package-announce@lists.fedoraproject.org>
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 43 Update: libcoap-4.3.5a-1.fc43
Date:  Fri, 05 Dec 2025 02:11:54 +0000
Message-ID:  <20251205021154.5AB027FD6E@bastion01.rdu3.fedoraproject.org>
Archive-link:  Article

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d408d76c4a 2025-12-05 02:08:09.994420+00:00 -------------------------------------------------------------------------------- Name : libcoap Product : Fedora 43 Version : 4.3.5a Release : 1.fc43 URL : https://libcoap.net/ Summary : C library implementation of CoAP Description : The Constrained Application Protocol (CoAP) is a specialized web transfer protocol for use with constrained nodes and constrained networks in the Internet of Things. The protocol is designed for machine-to-machine (M2M) applications such as smart energy and building automation. libcoap implements a lightweight application-protocol for devices with constrained resources such as computing power, RF range, memory, bandwidth, or network packet sizes. This protocol, CoAP, was standardized in the IETF working group "CoRE" as RFC 7252. -------------------------------------------------------------------------------- Update Information: Update to security release 4.3.5a -------------------------------------------------------------------------------- ChangeLog: * Sat Nov 29 2025 Peter Robinson <pbrobinson@gmail.com> - 4.3.5a-1 - Update to 4.3.5a -------------------------------------------------------------------------------- References: [ 1 ] Bug #2388738 - CVE-2025-50518 libcoap: Libcoap Use-After-Free Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388738 [ 2 ] Bug #2388740 - CVE-2025-50518 libcoap: Libcoap Use-After-Free Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388740 [ 3 ] Bug #2416889 - CVE-2025-65493 libcoap: libcoap denial of service [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2416889 [ 4 ] Bug #2416890 - CVE-2025-65494 libcoap: libcoap denial of service [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2416890 [ 5 ] Bug #2416891 - CVE-2025-65493 libcoap: libcoap denial of service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2416891 [ 6 ] Bug #2416892 - CVE-2025-65495 libcoap: libcoap denial of service [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2416892 [ 7 ] Bug #2416893 - CVE-2025-65493 libcoap: libcoap denial of service [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2416893 [ 8 ] Bug #2416894 - CVE-2025-65494 libcoap: libcoap denial of service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2416894 [ 9 ] Bug #2416895 - CVE-2025-65495 libcoap: libcoap denial of service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2416895 [ 10 ] Bug #2416896 - CVE-2025-65494 libcoap: libcoap denial of service [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2416896 [ 11 ] Bug #2416897 - CVE-2025-65495 libcoap: libcoap denial of service [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2416897 [ 12 ] Bug #2417721 - CVE-2025-65496 libcoap: NULL pointer dereference during DTLS operations [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417721 [ 13 ] Bug #2417722 - CVE-2025-65496 libcoap: NULL pointer dereference during DTLS operations [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2417722 [ 14 ] Bug #2417723 - CVE-2025-65497 libcoap: NULL pointer dereference during DTLS operations [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417723 [ 15 ] Bug #2417724 - CVE-2025-65497 libcoap: NULL pointer dereference during DTLS operations [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2417724 [ 16 ] Bug #2417725 - CVE-2025-65498 libcoap: NULL pointer dereference during DTLS operations [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417725 [ 17 ] Bug #2417726 - CVE-2025-65498 libcoap: NULL pointer dereference during DTLS operations [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2417726 [ 18 ] Bug #2417727 - CVE-2025-65499 libcoap: NULL pointer dereference during DTLS operations [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417727 [ 19 ] Bug #2417728 - CVE-2025-65499 libcoap: NULL pointer dereference during DTLS operations [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2417728 [ 20 ] Bug #2417729 - CVE-2025-65500 libcoap: NULL pointer dereference during DTLS operations [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417729 [ 21 ] Bug #2417730 - CVE-2025-65500 libcoap: NULL pointer dereference during DTLS operations [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2417730 [ 22 ] Bug #2417732 - CVE-2025-65501 libcoap: NULL pointer dereference during DTLS operations [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2417732 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d408d76c4a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds