Debian alert DLA-4658-1 (librabbitmq)
| From: | Chris Lamb <lamby@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4658-1] librabbitmq security update | |
| Date: | Tue, 30 Jun 2026 16:20:54 -0700 | |
| Message-ID: | <178284155931.3708433.1278581225278239294@bigcat> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4658-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb June 30, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : librabbitmq Version : 0.10.0-1+deb11u2 0.11.0-1+deb12u2 CVE ID : CVE-2026-44235 CVE-2026-44236 Two issues were discovered in librabbitmq, a C-language client library used to communicate with RabbitMQ servers using the Advanced Message Queuing Protocol (AMQP). CVE-2026-44235 A size_t underflow in AMQP frame length computation could have led to an out-of-bounds read. CVE-2026-44236 A heap buffer overflow in AMQP login handshake via undersized connection.tune.frame_max. For Debian 11 bullseye, these problems have been fixed in version 0.10.0-1+deb11u2. For Debian 12 bookworm, these problems have been fixed in version 0.11.0-1+deb12u2. We recommend that you upgrade your librabbitmq packages. For the detailed security status of librabbitmq please refer to its security tracker page at: https://security-tracker.debian.org/tracker/librabbitmq Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmpEANQACgkQHpU+J9Qx HlgeEhAAnvCzO/ARkLHoAVBIain9iF5ipwQS/VYv2Hys3spROcApybNP2/mwPJh5 4xLLox7gsDGFGvilfJRB9iasjyzuI6/uarzZirXj5/tPL8u710nXfcJYz3gsx9Wj vXHd1tUZsSGLBV0H/Jn27uXVtVXjcXqZKyBihZwRgVghbu93nOSp6InypOZK+PEU BffOBAJRKpW0SXkiPVBVcOT/FBd31l4gXDsL+NRq2g4QwP2qmZrh//9A+HiyfpD9 5qZasz1ZtkATkNfQDhxfLQx3fnO4wyxjanY95D6xKaJpL3FRA4FncXa7StnZTbDM EyBe2ogE9Cu/VrCb15eLLvDVs/qqMBvLlTW3+a+PPAlC0KIWAaQE4T8J049Xw6Rb 0/qTHEBQLfftsyqwmO49iDIp6tZ1TGrEcbw+6cVQpU9G2OE7sW4bhpNuNOruhYfX jVoKBQTWhxynssjovGVT+RDPYSFhO9kiZFiGYdrINKZdtSL1UQmozhed+Qxzcu5F EUedOwRGfDDNav45ib50aaOWhyhVq+JSkKG5Q9njVHseCcXT9LrTnWeVdwH7QK2c e3IuG1koc5yQ/8y6LB/Zh5fcpwF1+OsYPH3mcmrNWCP6UVn5chrVUrIIeqPwM00Z 6iEWVyHmxuOYVzMjoXkhO+wSWkvzQENwibJNevY5ixkVHg2s95k= =7KNs -----END PGP SIGNATURE-----
