SB2024042484 - Fedora 39 update for matrix-synapse, rust-pythonize



SB2024042484 - Fedora 39 update for matrix-synapse, rust-pythonize

Published: April 24, 2024

Security Bulletin ID SB2024042484
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect calculation (CVE-ID: CVE-2024-31208)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper calculation of the auth chain cover index in auth chain indexing when processing specially crafted events from a remote room member. A remote user can send specially crafted events to cause a denial of service.

Exploitation can lead to disk fill and high CPU usage. Servers in private federations, or those that do not federate, are not affected.


Remediation

Install update from vendor's website.