Ubuntu alert USN-8437-1 (librabbitmq)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8437-1] rabbitmq-c vulnerabilities | |
| Date: | Tue, 16 Jun 2026 16:18:03 +0000 | |
| Message-ID: | <E1wZWUF-0003P8-9Q@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8437-1 June 16, 2026 librabbitmq vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in rabbitmq-c. Software Description: - librabbitmq: AMQP client library written in C Details: It was discovered that rabbitmq-c exposed credentials in command-line arguments under certain circumstances. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2023-35789) It was discovered that rabbitmq-c incorrectly handled AMQP frame lengths under certain circumstances, which could lead to an out-of-bounds read. A remote attacker could possibly use this issue to cause rabbitmq-c to crash, resulting in a denial of service. (CVE-2026-44235) It was discovered that rabbitmq-c incorrectly handled AMQP login handshakes under certain circumstances, which could lead to a heap buffer overflow. A remote attacker could possibly use this issue to cause rabbitmq-c to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-44236) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS amqp-tools 0.15.0-1ubuntu0.26.04.1 librabbitmq4 0.15.0-1ubuntu0.26.04.1 Ubuntu 25.10 amqp-tools 0.15.0-1ubuntu0.25.10.1 librabbitmq4 0.15.0-1ubuntu0.25.10.1 Ubuntu 24.04 LTS amqp-tools 0.11.0-1ubuntu0.1 librabbitmq4 0.11.0-1ubuntu0.1 Ubuntu 22.04 LTS amqp-tools 0.10.0-1ubuntu2.1 librabbitmq4 0.10.0-1ubuntu2.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8437-1 CVE-2023-35789, CVE-2026-44235, CVE-2026-44236 Package Information: https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1... https://launchpad.net/ubuntu/+source/librabbitmq/0.15.0-1... https://launchpad.net/ubuntu/+source/librabbitmq/0.11.0-1... https://launchpad.net/ubuntu/+source/librabbitmq/0.10.0-1...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoxdyoACgkQcpJm3tlz hgGs2g/9EnB9/+yreN1kE/vPJyVUUtkfXxXWVx/Og0atcqOLwMnN5CYF2UKsEIFl KU5pnfWRD+R2g0S21NqMxI08zskm8S8YKTwCp/mSKg7JDSd4SdLGE2PGlQ+HKz68 W66ZcjEnVAjhoFo8zD4kejIHdtzeTb6yZVfkgqgdezw0uYTt48zuUw9mDKRmR8UO GNYZNPIP7FwPfz+j3zE2OB3xPc+DVB3XHsuHbOlqC9WFM/aFIxbAPNeN07re54Nk Lm342y10ECtcPoySkOcL1qW7cpxrfOdeLhL4Nsm0e3yX+TsMgsQo/e10DKfTZ9hz K03MYlroqzwxmByJZd/fiX2YXgYjHn9CQpi9+ELI3XAb3v1hhiTpP+RdRX/h1yZj HgyjUyQuKwM53nB/KZ/bLliPleqrCWCotVagfRH0KIEIrhzts8J9BQL9JO0EMOlX FMvUCW5UwTzry6DpzqbeDiYr7IZI7eaq+FbhgbsBbx7SM18L4/tLikI1XS4yvy8Z 5qw3iQWeIXyeczwCHT5MGBveh8vW9nynKjBqnZCMhUr1rpopU/WVC2JXbSqBmRPm Q2ZUJijWXbxnDIk4hly3sIRT5VZH17cAJ/OsNPTzqrUfgd5HVT8zkzP9DoPquWy8 fF3ukqUDyCmXqN719cYcKkTLWb2Xs/FSwOFOACkmful8l18MO+E= =Tet5 -----END PGP SIGNATURE-----
