Back Linuxsecurity Fedora 43 Coturn 4.15.0 Security Advisory Fixes STUN Issues 2026
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
The Coturn TURN Server is a VoIP media traffic NAT traversal server and gateway.
It can be used as a general-purpose network traffic TURN server/gateway, too.
This implementation also includes some extra features. Supported RFCs:
- RFC 5766 - base TURN specs
- RFC 6062 - TCP relaying TURN extension
- RFC 6156 - IPv6 extension for TURN
- Experimental DTLS support as client protocol.
- RFC 3489 - "classic" STUN
- RFC 5389 - base "new" STUN specs
- RFC 5769 - test vectors for STUN protocol testing
- RFC 5780 - NAT behavior discovery support
The implementation fully supports the following client-to-TURN-server protocols:
- TCP (per RFC 5766 and RFC 6062)
- TLS (per RFC 5766 and RFC 6062); TLS1.0/TLS1.1/TLS1.2
- DTLS (experimental non-standard feature)
Supported relay protocols:
Supported user databases (for user repository, with passwords or keys, if
authentication is required):
Redis can also be used for status and statistics storage and notification.
Supported TURN authentication mechanisms:
- TURN REST API (a modification of the long-term mechanism, for time-limited
secret-based authentication, for WebRTC applications)
The load balancing can be implemented with the following tools (either one or a
combination of them):
- network load-balancer server
- DNS-based load balancing
- built-in ALTERNATE-SERVER mechanism.
Coturn 4.15.0 Security Ignore STUN attributes after MESSAGE-INTEGRITY (GHSA-5538-7cxj-5jcc). Per RFC 8489 §9 / RFC 5389 §15.4, attributes following MESSAGE-INTEGRITY (other than FINGERPRINT) must be ignored, but coturn processed the full attribute list. This also fixes an interop bug where an RFC 8489 client sending MESSAGE-INTEGRITY- SHA256 after MESSAGE-INTEGRITY was wrongly answered with error 420. Bind mobility session-resume to the original allocation owner — a MOBILITY- TICKET resume is now only accepted from the user that created the allocation. Reject ACME requests via signed 400 response instead of silently dropping them. Reset the reused UDP receive-buffer offset in the DTLS listener. Zeroed channel-data padding in stun_init_channel_message_str so uninitialized stack bytes never reach the wire. Fixed a uint16_t truncation overflow when computing STUN message length. Fixed an off-by-one write past the realm buffer in redis_list_admin_users. Fixed a size_t underflow in t...
* Fri Jul 24 2026 Robert Scheck - 4.15.0-1 - Upgrade to 4.15.0 (#2506022) * Wed Jul 15 2026 Fedora Release Engineering - 4.14.0-3 - Rebuilt for
* Fri Jul 24 2026 Robert Scheck - 4.15.0-1 - Upgrade to 4.15.0 (#2506022) * Wed Jul 15 2026 Fedora Release Engineering - 4.14.0-3 - Rebuilt for
[ 1 ] Bug #2506022 - coturn-4.15.0 is available
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-02d5b68472' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
