Linuxsecurity Critical Vulnerabilities in rabbitmq-c Affect Multiple Ubuntu Releases
Article Content
- •rabbitmq-c vulnerabilities affect Ubuntu 22.04, 24.04, 25.10, and 26.04 LTS.
- •CVE-2023-35789 exposes credentials, while CVE-2026-44235 and CVE-2026-44236 pose serious denial of service and remote code execution risks.
- •Immediate updates are required to mitigate these vulnerabilities across affected systems.
Multiple security vulnerabilities were discovered in rabbitmq-c, affecting Ubuntu 22.04 LTS, 24.04 LTS, 25.10, and 26.04 LTS. CVE-2023-35789 allows local attackers to expose credentials through command-line arguments. CVE-2026-44235 involves improper handling of AMQP frame lengths, leading to potential denial of service via remote exploitation. Additionally, CVE-2026-44236 presents a heap buffer overflow risk during AMQP login handshakes, which could allow remote code execution. These issues necessitate immediate updates to the affected packages to mitigate risks. The vulnerabilities were confirmed on June 16, 2026, with patches available for all affected versions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2023-35789 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…