SB2024042485 - Fedora 38 update for matrix-synapse, rust-pythonize
Published: April 24, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect calculation (CVE-ID: CVE-2024-31208)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper calculation of the auth chain cover index in auth chain indexing when processing specially crafted events from a remote room member. A remote user can send specially crafted events to cause a denial of service.
Exploitation can lead to disk fill and high CPU usage. Servers in private federations, or those that do not federate, are not affected.
Remediation
Install update from vendor's website.