--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-0f75cd00ff
2026-09-28 01:12:52.002828+00:00
--------------------------------------------------------------------------------

Name        : libmaxminddb
Product     : Fedora 44
Version     : 1.14.0
Release     : 1.fc44
URL         : https://maxmind.github.io/libmaxminddb/
Summary     : C library for reading MaxMind DB files
Description :
The libmaxminddb library provides a C library for reading MaxMind DB
files, including the GeoIP2 databases from MaxMind. This is a custom
binary format designed to facilitate fast lookups of IP addresses
while allowing for great flexibility in the type of data associated
with an address.

The MaxMind DB format is an open file format. The specification is
available at https://maxmind.github.io/MaxMind-DB/ and licensed under
the Creative Commons Attribution-ShareAlike 3.0 Unported License.

--------------------------------------------------------------------------------
Update Information:

libmaxminddb 1.14.0
Bounded the resources that MMDB_get_entry_data_list() spends decoding a
  single entry. A crafted database could nest data-section pointers to shared
  targets so that decoding one entry cost exponential time and memory, or point
  many times at one large value so that a caller copying the result materialized
  far more data than the file holds. The decoder now follows the Reader Resource
  Limits section of the MaxMind DB specification. Each call is limited to 65,536
  values and 2 MiB of string and bytes payload, in addition to the existing
  recursive-decoder depth limit of 512. See the MMDB_get_entry_data_list()
  documentation for details.
Exceeding a limit returns the new MMDB_DECODER_LIMIT_ERROR status. A
    full-list failure leaves the output set to NULL.
MMDB_get_value(), MMDB_vget_value(), and MMDB_aget_value() now return
    MMDB_DECODER_LIMIT_ERROR instead of MMDB_INVALID_DATA_ERROR when they
    skip a subtree past the depth limit.
MMDB_open() returns MMDB_INVALID_METADATA_ERROR when metadata processing
    exceeds a decoder limit.
The limits can be raised when building the library with
    -DMAXIMUM_DATA_STRUCTURE_DEPTH, -DMAXIMUM_DATA_STRUCTURE_VALUES, and
    -DMAXIMUM_DATA_STRUCTURE_BYTES.
Fixed an out-of-bounds read in MMDB_lookup_sockaddr() when callers passed a
  sockaddr with an unsupported address family. The function now rejects any
  family other than AF_INET and AF_INET6 with
  MMDB_INVALID_NETWORK_ADDRESS_ERROR.
Fixed metadata parsing for files that end immediately after the
  \xAB\xCD\xEFMaxMind.com marker. Such files are now rejected as invalid
  metadata instead of allowing a zero-length metadata section to reach the
  decoder.
Fixed search-tree validation for records that point into the 16-byte separator
  before the data section. These records are now rejected as corrupt instead of
  being exposed as apparent data entries with underflowed offsets.
MMDB_read_node() now returns MMDB_CORRUPT_SEARCH_TREE_ERROR instead of
  MMDB_SUCCESS with MMDB_RECORD_TYPE_INVALID record types when a node's
  child record is invalid.
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep 12 2026 Robert Scheck <[email protected]> 1.14.0-1
- Upgrade to 1.14.0 (#2529974)
* Thu Jul 16 2026 Fedora Release Engineering <[email protected]> - 
1.13.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2529974 - libmaxminddb-1.14.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2529974
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-0f75cd00ff' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to