Back Linuxsecurity Fedora 44 coturn 4.17.2 Denial of Service Fix Advisory 2026
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
The Coturn TURN Server is a VoIP media traffic NAT traversal server and gateway.
It can be used as a general-purpose network traffic TURN server/gateway, too.
This implementation also includes some extra features. Supported RFCs:
- RFC 5766 - base TURN specs
- RFC 6062 - TCP relaying TURN extension
- RFC 6156 - IPv6 extension for TURN
- Experimental DTLS support as client protocol.
- RFC 3489 - "classic" STUN
- RFC 5389 - base "new" STUN specs
- RFC 5769 - test vectors for STUN protocol testing
- RFC 5780 - NAT behavior discovery support
The implementation fully supports the following client-to-TURN-server protocols:
- TCP (per RFC 5766 and RFC 6062)
- TLS (per RFC 5766 and RFC 6062); TLS1.0/TLS1.1/TLS1.2
- DTLS (experimental non-standard feature)
Supported relay protocols:
Supported user databases (for user repository, with passwords or keys, if
authentication is required):
Redis can also be used for status and statistics storage and notification.
Supported TURN authentication mechanisms:
- TURN REST API (a modification of the long-term mechanism, for time-limited
secret-based authentication, for WebRTC applications)
The load balancing can be implemented with the following tools (either one or a
combination of them):
- network load-balancer server
- DNS-based load balancing
- built-in ALTERNATE-SERVER mechanism.
Coturn 4.17.2 What's Changed Fix outgoing UDP TTL pinned to 1 on client-facing sockets Coturn 4.17.1 Gate merges on the more tests suites build: Drop ginstall detection in configure Flash before socket close Coturn 4.17.0 Upgrade notes Three defaults changed in this release. Read these before upgrading. DTLS listeners are now opt-in. The server no longer starts DTLS listeners unless --dtls is given. A deployment that relied on DTLS being up by default will stop serving DTLS clients after the upgrade, without an error. The deprecated --no- dtls / --no-dtls=false spellings are still accepted and now warn. Stateless nonce is on by default. Challenge nonces are authenticated timestamp cookies rather than a random value stored per session, so unauthenticated UDP requests are answered from the listener without allocating a session. Two consequences: The challenge NONCE is now 24 characters instead of 16. RFC 8489 requires clients to treat it as an opaque string of up to...
* Sun Aug 9 2026 Robert Scheck - 4.17.2-1 - Upgrade to 4.17.2 (#2511357 #c2) * Sat Aug 8 2026 Robert Scheck - 4.17.1-1 - Upgrade to 4.17.1 (#2511357 #c1) * Wed Aug 5 2026 Robert Scheck - 4.17.0-1 - Upgrade to 4.17.0 (#2511357)
* Sun Aug 9 2026 Robert Scheck - 4.17.2-1 - Upgrade to 4.17.2 (#2511357 #c2) * Sat Aug 8 2026 Robert Scheck - 4.17.1-1 - Upgrade to 4.17.1 (#2511357 #c1) * Wed Aug 5 2026 Robert Scheck - 4.17.0-1 - Upgrade to 4.17.0 (#2511357)
[ 1 ] Bug #2514255 - CVE-2026-73215 coturn: Coturn: Denial of Service due to incorrect port allocation
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-50c75def83' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
