Bug 2424854
| Summary: | CVE-2025-68667 catalyst: continuwuity Has an Unintended Proxy or Intermediary and Improper Input Validation [fedora-43] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Dhananjay Arunesh <darunesh> |
| Component: | catalyst | Assignee: | Orion Poplawski <orion> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | urgent | Docs Contact: | |
| Priority: | urgent | ||
| Version: | 43 | CC: | mkrupcale, orion |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["124d605c-8a9d-4284-b5d8-664f15ec07f0"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2026-05-25 18:55:51 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2424789 | ||
|
Description
Dhananjay Arunesh
2025-12-24 10:56:33 UTC
AFAICT the conduit referenced by CVE-2025-68667 [1] is a Matrix chat server, completely separate from the conduit [2,3] used by the Fedora catalyst package. The conduit used by catalyst is a HPC data exchange library. So this issue as well as [4] can probably be closed. [1] https://access.redhat.com/security/cve/CVE-2025-68667 [2] https://llnl-conduit.readthedocs.io/en/latest/ [3] https://github.com/llnl/conduit [4] https://bugzilla.redhat.com/show_bug.cgi?id=2424853 Thanks for the review. |