|
|
Log in / Subscribe / Register

Debian alert DLA-4763-1 (librabbitmq)

From:  Abhijith PA <abhijith@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4763-1] librabbitmq security update
Date:  Mon, 31 Aug 2026 15:04:07 +0530
Message-ID:  <apVKj7lKOAZmPs_P@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4763-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Abhijith PA August 31, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : librabbitmq Version : 0.10.0-1+deb11u3 0.11.0-1+deb12u3 CVE ID : CVE-2026-59986 CVE-2026-61547 Two issues has been found in librabbitmq, AMQP client library and tools written in C. CVE-2026-59986 The bounds check in librabbitmq/amqp_private.h function overflows causing out-of-bounds read on 32-bit systems which in turn causes information disclosure or denial of service. CVE-2026-61547 A heap buffer overflow exists in rabbitmq-c when the public amqp_send_frame() API is used to serialize an oversized AMQP_FRAME_BODY. An application that passes an oversized body frame to amqp_send_frame() can trigger a heap out-of-bounds write, resulting in process crash and memory corruption. For Debian 11 bullseye, these problems have been fixed in version 0.10.0-1+deb11u3. For Debian 12 bookworm, these problems have been fixed in version 0.11.0-1+deb12u3. We recommend that you upgrade your librabbitmq packages. For the detailed security status of librabbitmq please refer to its security tracker page at: https://security-tracker.debian.org/tracker/librabbitmq Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqVSo8ACgkQhj1N8u2c KO/irBAAj1yh1i/oC0U5ygv+joOTGbGud+tYRAUxPCBUqWZ4JdSzpaW6dfOZ+WO0 3s4EuroyEvE4k+7XxQnxuVlDA697/Re2PSo+fLezVTDUrHIoKlddql0Iy+6BB9Vq ve0HRQCEVNmXjYrlTxXVmMufkJ9qabjsSujPAiO7EHpYXV+BtMEI/YNSvOn5kqHv 5yq0uwA07Rg5BbbIwuwzdoGovn2Qe3rY4GkJOdQbcxQrNXLUR/Oq9bQvMWW4XwhD Q+V29rYZW0vnGLdrzn1dRkUVkmMDQWx8MXxKPJl+PEXKeRaUB5pfKt62FbEh8CmK EPWNbdHNeadKUO78pyowtb3Dvauk9jx7qOCqWW4eGnwDR4xWp4puT3jp7k33qrdv hwKALr36XYwHCqiqHE2/D37zUxKiOR8NvkfpOSshT7cDoRHQ+AihheR1u/u04dn/ wfdbne41v4oybIr7U1n9IjEYF3E//EmtTPa0klYzNz0MFhIGmlfZk/GyxxanraLG +ZNU8bMkD1yICBfma8A+qN0I50PopONAnqXUPlI13HzxvnHfUl4PJRnpbB1BiATi UhJHsFe6i79UdhA0g8KO/j4AUzi7F4rTLEu/TIlwOjHWhd1tM7d3NLAgXP1IY3iX 8DVNOSySQJp4LZptzFFCp7yYUqZRQqsE/mN6JPgopQtTwaEaLRI= =UyNq -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds