Bug 2540087

Summary: CVE-2026-66072 rabbitmq-server: RabbitMQ: Denial of Service via atom table exhaustion in stream chunk_selector [fedora-all]
Product: [Fedora] Fedora Reporter: Jon Weiser <jweiser>
Component: rabbitmq-serverAssignee: Peter Lemenkov <lemenkov>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: lemenkov, rjones
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["c7d78bfb-94a1-4b16-9b15-d92aae2673f8"]}
Fixed In Version: rabbitmq-server-4.3.6-1.fc46 rabbitmq-server-4.3.6-1.fc45 rabbitmq-server-4.2.9-2.fc44 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-10-09 15:44:04 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2539758    

Description Jon Weiser 2026-09-24 14:05:14 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_selector/1 calls binary_to_atom on the raw client-supplied <<"chunk_selector">> property from post-auth subscribe and resolve_offset_spec frames, with no whitelist and no existing guard. An authenticated stream client with read access to any stream can crash the broker node. Preconditions include rabbitmq_stream plugin enabled Authenticated stream-protocol user with read access to at least one stream. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1.

Comment 1 Peter Lemenkov 2026-10-09 13:24:19 UTC
This issue is already fixed upstream in RabbitMQ 4.3.6, which is the version currently built for Fedora rawhide (rabbitmq-server-4.3.6-1.fc46) and Fedora 45 (rabbitmq-server-4.3.6-1.fc45).

Fedora 44 (currently 4.2.9) and Fedora 43 (currently 4.0.9) still need attention; backports/rebases for the still-supported stable branches are being worked on. Leaving this report open to track that remaining work.

Comment 2 Peter Lemenkov 2026-10-09 15:44:04 UTC
This issue is already addressed in the rabbitmq-server builds currently shipped in all maintained Fedora branches:

  * Fedora rawhide: rabbitmq-server-4.3.6-1.fc46
  * Fedora 45:      rabbitmq-server-4.3.6-1.fc45
  * Fedora 44:      rabbitmq-server-4.2.9-2.fc44

No new build is required for these branches, so closing as CURRENTRELEASE.

Fedora 43 (rabbitmq-server-4.0.9) will NOT be updated for this CVE batch: the upstream 4.0.x line ended at 4.0.9 (later 4.0.x fixes are commercial-only, with no public OSS release) and Fedora 43 reaches end of life on 2026-12-09, so a backport to F43 is not worthwhile.