-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-92578cf596 2026-09-28 01:16:42.090952+00:00 --------------------------------------------------------------------------------
Name : libmaxminddb Product : Fedora 43 Version : 1.14.0 Release : 1.fc43 URL : https://maxmind.github.io/libmaxminddb/ Summary : C library for reading MaxMind DB files Description : The libmaxminddb library provides a C library for reading MaxMind DB files, including the GeoIP2 databases from MaxMind. This is a custom binary format designed to facilitate fast lookups of IP addresses while allowing for great flexibility in the type of data associated with an address. The MaxMind DB format is an open file format. The specification is available at https://maxmind.github.io/MaxMind-DB/ and licensed under the Creative Commons Attribution-ShareAlike 3.0 Unported License. -------------------------------------------------------------------------------- Update Information: libmaxminddb 1.14.0 Bounded the resources that MMDB_get_entry_data_list() spends decoding a single entry. A crafted database could nest data-section pointers to shared targets so that decoding one entry cost exponential time and memory, or point many times at one large value so that a caller copying the result materialized far more data than the file holds. The decoder now follows the Reader Resource Limits section of the MaxMind DB specification. Each call is limited to 65,536 values and 2 MiB of string and bytes payload, in addition to the existing recursive-decoder depth limit of 512. See the MMDB_get_entry_data_list() documentation for details. Exceeding a limit returns the new MMDB_DECODER_LIMIT_ERROR status. A full-list failure leaves the output set to NULL. MMDB_get_value(), MMDB_vget_value(), and MMDB_aget_value() now return MMDB_DECODER_LIMIT_ERROR instead of MMDB_INVALID_DATA_ERROR when they skip a subtree past the depth limit. MMDB_open() returns MMDB_INVALID_METADATA_ERROR when metadata processing exceeds a decoder limit. The limits can be raised when building the library with -DMAXIMUM_DATA_STRUCTURE_DEPTH, -DMAXIMUM_DATA_STRUCTURE_VALUES, and -DMAXIMUM_DATA_STRUCTURE_BYTES. Fixed an out-of-bounds read in MMDB_lookup_sockaddr() when callers passed a sockaddr with an unsupported address family. The function now rejects any family other than AF_INET and AF_INET6 with MMDB_INVALID_NETWORK_ADDRESS_ERROR. Fixed metadata parsing for files that end immediately after the \xAB\xCD\xEFMaxMind.com marker. Such files are now rejected as invalid metadata instead of allowing a zero-length metadata section to reach the decoder. Fixed search-tree validation for records that point into the 16-byte separator before the data section. These records are now rejected as corrupt instead of being exposed as apparent data entries with underflowed offsets. MMDB_read_node() now returns MMDB_CORRUPT_SEARCH_TREE_ERROR instead of MMDB_SUCCESS with MMDB_RECORD_TYPE_INVALID record types when a node's child record is invalid. -------------------------------------------------------------------------------- ChangeLog: * Sat Sep 12 2026 Robert Scheck <[email protected]> 1.14.0-1 - Upgrade to 1.14.0 (#2529974) * Thu Jul 16 2026 Fedora Release Engineering <[email protected]> - 1.13.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2529974 - libmaxminddb-1.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2529974 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-92578cf596' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
