Critical Security Flaws in Fedora RPKI and Syslog Components

Critical Security Flaws in Fedora RPKI and Syslog Components

First seen 22 Jul 2026, 09:46 UTC Linuxsecurity 90% similarity 74.0

Article Content

Browse articles
ThreatCluster

Multiple critical vulnerabilities have been identified in Fedora's RPKI and syslog components, affecting versions 43 and 44. The vulnerabilities include path traversal issues and improper error handling, with CVEs assigned as CVE-2026-49232 and CVE-2026-49233. These flaws were discovered during a security audit conducted by X41 D-Sec, funded by the Sovereign Tech Agency. Users are advised to upgrade to the latest versions immediately to mitigate potential exploitation risks. The vulnerabilities could allow unauthorized access and denial of service attacks, posing significant risks to systems utilizing these components. The affected systems include Fedora 43 and 44 distributions, with specific advisories issued for rust-rpki, rust-syslog, and rust-routinator. The updates are available via the dnf package manager, and users are encouraged to apply them promptly.

Key Points: • Critical vulnerabilities identified in Fedora's RPKI and syslog components. • Path traversal and error handling flaws assigned CVEs CVE-2026-49232 and CVE-2026-49233. • Immediate upgrades recommended for affected Fedora versions 43 and 44.

ThreatCluster AI

Timeline

2026-06-08
CVE-2026-49232 published
A critical vulnerability in Fedora's syslog component was disclosed, allowing potential unauthorized access.
Linuxsecurity
2026-06-08
CVE-2026-49233 published
A path traversal vulnerability in Fedora's RPKI component was disclosed, posing significant security risks.
Linuxsecurity
2026-06-08
CVE-2026-49234 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-49235 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
Security advisories issued for Fedora 43 and 44
Fedora released critical updates addressing vulnerabilities in rust-rpki and rust-syslog components, urging users to upgrade immediately.
Linuxsecurity

Community

Browse all →