-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4763-1                [email protected]
https://www.debian.org/lts/security/                          Abhijith PA
August 31, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : librabbitmq
Version        : 0.10.0-1+deb11u3 0.11.0-1+deb12u3
CVE ID         : CVE-2026-59986 CVE-2026-61547

Two issues has been found in librabbitmq, AMQP client library and
tools written in C.

CVE-2026-59986

    The bounds check in librabbitmq/amqp_private.h function overflows
    causing out-of-bounds read on 32-bit systems which in turn causes
    information disclosure or denial of service.

CVE-2026-61547

    A heap buffer overflow exists in rabbitmq-c when the public
    amqp_send_frame() API is used to serialize an oversized
    AMQP_FRAME_BODY. An application that passes an oversized body
    frame to amqp_send_frame() can trigger a heap out-of-bounds write,
    resulting in process crash and memory corruption.

For Debian 11 bullseye, these problems have been fixed in version
0.10.0-1+deb11u3.

For Debian 12 bookworm, these problems have been fixed in version
0.11.0-1+deb12u3.

We recommend that you upgrade your librabbitmq packages.

For the detailed security status of librabbitmq please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/librabbitmq

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqVSo8ACgkQhj1N8u2c
KO/irBAAj1yh1i/oC0U5ygv+joOTGbGud+tYRAUxPCBUqWZ4JdSzpaW6dfOZ+WO0
3s4EuroyEvE4k+7XxQnxuVlDA697/Re2PSo+fLezVTDUrHIoKlddql0Iy+6BB9Vq
ve0HRQCEVNmXjYrlTxXVmMufkJ9qabjsSujPAiO7EHpYXV+BtMEI/YNSvOn5kqHv
5yq0uwA07Rg5BbbIwuwzdoGovn2Qe3rY4GkJOdQbcxQrNXLUR/Oq9bQvMWW4XwhD
Q+V29rYZW0vnGLdrzn1dRkUVkmMDQWx8MXxKPJl+PEXKeRaUB5pfKt62FbEh8CmK
EPWNbdHNeadKUO78pyowtb3Dvauk9jx7qOCqWW4eGnwDR4xWp4puT3jp7k33qrdv
hwKALr36XYwHCqiqHE2/D37zUxKiOR8NvkfpOSshT7cDoRHQ+AihheR1u/u04dn/
wfdbne41v4oybIr7U1n9IjEYF3E//EmtTPa0klYzNz0MFhIGmlfZk/GyxxanraLG
+ZNU8bMkD1yICBfma8A+qN0I50PopONAnqXUPlI13HzxvnHfUl4PJRnpbB1BiATi
UhJHsFe6i79UdhA0g8KO/j4AUzi7F4rTLEu/TIlwOjHWhd1tM7d3NLAgXP1IY3iX
8DVNOSySQJp4LZptzFFCp7yYUqZRQqsE/mN6JPgopQtTwaEaLRI=
=UyNq
-----END PGP SIGNATURE-----

Reply via email to