More information about this security flaw is available in the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=2328732 Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The update for rustls itself that fixes this issue has already been submitted: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-a3bbb42db3 I still need to investigate which applications (if any) are actually affected by this issue, and rebuild them against the fixed version.
bad bot.
This has been addressed in rust-rustls and as far as I can tell, no applications in Fedora that depend on rustls are affected.