Critical Vulnerabilities in rabbitmq-c Affect Multiple Ubuntu Releases

Critical Vulnerabilities in rabbitmq-c Affect Multiple Ubuntu Releases

First seen 16 Jun 2026, 17:12 UTC UbuntuLinuxsecurity 93% similarity 70.5

Article Content

Browse articles
ThreatCluster

Multiple security vulnerabilities were discovered in rabbitmq-c, affecting Ubuntu 22.04 LTS, 24.04 LTS, 25.10, and 26.04 LTS. CVE-2023-35789 allows local attackers to expose credentials through command-line arguments. CVE-2026-44235 involves improper handling of AMQP frame lengths, leading to potential denial of service via remote exploitation. Additionally, CVE-2026-44236 presents a heap buffer overflow risk during AMQP login handshakes, which could allow remote code execution. These issues necessitate immediate updates to the affected packages to mitigate risks. The vulnerabilities were confirmed on June 16, 2026, with patches available for all affected versions.

Key Points: • rabbitmq-c vulnerabilities affect Ubuntu 22.04, 24.04, 25.10, and 26.04 LTS. • CVE-2023-35789 exposes credentials, while CVE-2026-44235 and CVE-2026-44236 pose serious denial of service and remote code execution risks. • Immediate updates are required to mitigate these vulnerabilities across affected systems.

ThreatCluster AI How this analysis works

Timeline

2023-06-16
CVE-2023-35789 published
Local attackers can expose credentials in rabbitmq-c through command-line arguments, affecting Ubuntu 22.04 and 24.04 LTS.
Ubuntu
2026-06-16
CVE-2026-44235 and CVE-2026-44236 disclosed
Remote attackers can exploit rabbitmq-c vulnerabilities to cause denial of service and potentially execute arbitrary code.
Linuxsecurity
2026-06-16
Patches released for affected Ubuntu versions
Updates for rabbitmq-c vulnerabilities are available for Ubuntu 22.04, 24.04, 25.10, and 26.04 LTS.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story