A flaw was found in zeromq before 4.3.3. The use of a static allocator with ZMTP v1 packets may lead to a heap based overflow. References: https://github.com/zeromq/libzmq/pull/3902 https://github.com/zeromq/libzmq/security/advisories/GHSA-fc3w-qxf5-7hp6 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=21984
Created zeromq tracking bugs for this issue: Affects: epel-all [bug 1921985] Affects: fedora-all [bug 1921987] Affects: openstack-rdo [bug 1921986] Created zeromq3 tracking bugs for this issue: Affects: epel-7 [bug 1921984]
Fixed by https://bodhi.fedoraproject.org/updates/FEDORA-2021-a01e258e6d
FEDORA-2021-8b3202b783 has been pushed to the Fedora 33 stable repository. If problem still persists, please make note of it in this bug report.
External References: https://github.com/zeromq/libzmq/security/advisories/GHSA-fc3w-qxf5-7hp6
FEDORA-EPEL-2021-5e4b80b9d8 has been pushed to the Fedora EPEL 8 stable repository. If problem still persists, please make note of it in this bug report.