Bug 2523472
| Summary: | CVE-2026-67214 frama-c: nanoid: Denial of Service via negative size input in non-secure module functions [fedora-all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Joel Chamberlain <jochambe> |
| Component: | frama-c | Assignee: | Jerry James <loganjerry> |
| Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | rawhide | CC: | Andre.MARONEZE, loganjerry |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["f541dbf1-ce45-491a-9832-abc0354b81a5"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2026-08-25 14:35:51 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2508411 | ||
|
Description
Joel Chamberlain
2026-08-25 14:33:27 UTC
The JavaScript code in the frama-c tarball is not used during the build and is not shipped in any binary RPM. It is completely irrelevant as far as Fedora is concerned. Please stop scanning it for vulnerabilities. They don't matter to Fedora. |