Back Linuxsecurity Fedora 43 rust-syslog Critical Path Traversal DoS Vuln 2026
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
Syslog message formatter and writer, supporting unix sockets, UDP and
Update routinator to the latest, pulling in updated dependencies (rpki and syslog), and switch fern to using syslog 7 instead of 6 for this update, and loosen the syslog version bound for ifcfg-devname. v0.15.2 This release fixes a number of vulnerabilities and security issues identified by a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency. We advise all users to upgrade at their earliest convenience. Security fixes Changed how transient errors when accepting incoming HTTP and RTR connections are handled: instead of exiting, a warning is printed and the error is ignored. ([#1099]) This issue was assigned CVE-2026-49232. Extended the check for illegal path components in rsync URIs to also include the authority and module parts. (via rpki-rs#370) This fixes a path traversal vulnerability that has been assigned CVE-2026-49233. Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373) This fixes a vulnerability that has been assigned CVE-2...
* Thu Jul 2 2026 Michel Lind - 7.0.0-2 - Commit rust2rpm.toml * Thu Jul 2 2026 Michel Lind - 7.0.0-1 - Update to version 7.0.0; Resolves RHBZ#2300127
* Thu Jul 2 2026 Michel Lind - 7.0.0-2 - Commit rust2rpm.toml * Thu Jul 2 2026 Michel Lind - 7.0.0-1 - Update to version 7.0.0; Resolves RHBZ#2300127
[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available [ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available [ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available [ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-659cb50390' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
