Debian alert DLA-4763-1 (librabbitmq)
| From: | Abhijith PA <abhijith@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4763-1] librabbitmq security update | |
| Date: | Mon, 31 Aug 2026 15:04:07 +0530 | |
| Message-ID: | <apVKj7lKOAZmPs_P@debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4763-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Abhijith PA August 31, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : librabbitmq Version : 0.10.0-1+deb11u3 0.11.0-1+deb12u3 CVE ID : CVE-2026-59986 CVE-2026-61547 Two issues has been found in librabbitmq, AMQP client library and tools written in C. CVE-2026-59986 The bounds check in librabbitmq/amqp_private.h function overflows causing out-of-bounds read on 32-bit systems which in turn causes information disclosure or denial of service. CVE-2026-61547 A heap buffer overflow exists in rabbitmq-c when the public amqp_send_frame() API is used to serialize an oversized AMQP_FRAME_BODY. An application that passes an oversized body frame to amqp_send_frame() can trigger a heap out-of-bounds write, resulting in process crash and memory corruption. For Debian 11 bullseye, these problems have been fixed in version 0.10.0-1+deb11u3. For Debian 12 bookworm, these problems have been fixed in version 0.11.0-1+deb12u3. We recommend that you upgrade your librabbitmq packages. For the detailed security status of librabbitmq please refer to its security tracker page at: https://security-tracker.debian.org/tracker/librabbitmq Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqVSo8ACgkQhj1N8u2c KO/irBAAj1yh1i/oC0U5ygv+joOTGbGud+tYRAUxPCBUqWZ4JdSzpaW6dfOZ+WO0 3s4EuroyEvE4k+7XxQnxuVlDA697/Re2PSo+fLezVTDUrHIoKlddql0Iy+6BB9Vq ve0HRQCEVNmXjYrlTxXVmMufkJ9qabjsSujPAiO7EHpYXV+BtMEI/YNSvOn5kqHv 5yq0uwA07Rg5BbbIwuwzdoGovn2Qe3rY4GkJOdQbcxQrNXLUR/Oq9bQvMWW4XwhD Q+V29rYZW0vnGLdrzn1dRkUVkmMDQWx8MXxKPJl+PEXKeRaUB5pfKt62FbEh8CmK EPWNbdHNeadKUO78pyowtb3Dvauk9jx7qOCqWW4eGnwDR4xWp4puT3jp7k33qrdv hwKALr36XYwHCqiqHE2/D37zUxKiOR8NvkfpOSshT7cDoRHQ+AihheR1u/u04dn/ wfdbne41v4oybIr7U1n9IjEYF3E//EmtTPa0klYzNz0MFhIGmlfZk/GyxxanraLG +ZNU8bMkD1yICBfma8A+qN0I50PopONAnqXUPlI13HzxvnHfUl4PJRnpbB1BiATi UhJHsFe6i79UdhA0g8KO/j4AUzi7F4rTLEu/TIlwOjHWhd1tM7d3NLAgXP1IY3iX 8DVNOSySQJp4LZptzFFCp7yYUqZRQqsE/mN6JPgopQtTwaEaLRI= =UyNq -----END PGP SIGNATURE-----
