-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4763-1 [email protected]
https://www.debian.org/lts/security/ Abhijith PA
August 31, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : librabbitmq
Version : 0.10.0-1+deb11u3 0.11.0-1+deb12u3
CVE ID : CVE-2026-59986 CVE-2026-61547
Two issues has been found in librabbitmq, AMQP client library and
tools written in C.
CVE-2026-59986
The bounds check in librabbitmq/amqp_private.h function overflows
causing out-of-bounds read on 32-bit systems which in turn causes
information disclosure or denial of service.
CVE-2026-61547
A heap buffer overflow exists in rabbitmq-c when the public
amqp_send_frame() API is used to serialize an oversized
AMQP_FRAME_BODY. An application that passes an oversized body
frame to amqp_send_frame() can trigger a heap out-of-bounds write,
resulting in process crash and memory corruption.
For Debian 11 bullseye, these problems have been fixed in version
0.10.0-1+deb11u3.
For Debian 12 bookworm, these problems have been fixed in version
0.11.0-1+deb12u3.
We recommend that you upgrade your librabbitmq packages.
For the detailed security status of librabbitmq please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/librabbitmq
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqVSo8ACgkQhj1N8u2c
KO/irBAAj1yh1i/oC0U5ygv+joOTGbGud+tYRAUxPCBUqWZ4JdSzpaW6dfOZ+WO0
3s4EuroyEvE4k+7XxQnxuVlDA697/Re2PSo+fLezVTDUrHIoKlddql0Iy+6BB9Vq
ve0HRQCEVNmXjYrlTxXVmMufkJ9qabjsSujPAiO7EHpYXV+BtMEI/YNSvOn5kqHv
5yq0uwA07Rg5BbbIwuwzdoGovn2Qe3rY4GkJOdQbcxQrNXLUR/Oq9bQvMWW4XwhD
Q+V29rYZW0vnGLdrzn1dRkUVkmMDQWx8MXxKPJl+PEXKeRaUB5pfKt62FbEh8CmK
EPWNbdHNeadKUO78pyowtb3Dvauk9jx7qOCqWW4eGnwDR4xWp4puT3jp7k33qrdv
hwKALr36XYwHCqiqHE2/D37zUxKiOR8NvkfpOSshT7cDoRHQ+AihheR1u/u04dn/
wfdbne41v4oybIr7U1n9IjEYF3E//EmtTPa0klYzNz0MFhIGmlfZk/GyxxanraLG
+ZNU8bMkD1yICBfma8A+qN0I50PopONAnqXUPlI13HzxvnHfUl4PJRnpbB1BiATi
UhJHsFe6i79UdhA0g8KO/j4AUzi7F4rTLEu/TIlwOjHWhd1tM7d3NLAgXP1IY3iX
8DVNOSySQJp4LZptzFFCp7yYUqZRQqsE/mN6JPgopQtTwaEaLRI=
=UyNq
-----END PGP SIGNATURE-----