Bug 2344555 - cosmic-store: openssl: CVE-2025-0977 / RUSTSEC-2025-0004: ssl::select_next_proto use after free
Summary: cosmic-store: openssl: CVE-2025-0977 / RUSTSEC-2025-0004: ssl::select_next_pr...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: cosmic-store
Version: 45
Hardware: Unspecified
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Ryan Brue
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: RUSTSEC-2025-0004
TreeView+ depends on / blocked
 
Reported: 2025-02-09 15:14 UTC by Fabio Valentini
Modified: 2026-08-17 13:33 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Fabio Valentini 2025-02-09 15:14:22 UTC
The version of the "openssl" crate bundled in this package is vulnerable to CVE-2025-0977 / RUSTSEC-2025-0004.

c.f. https://rustsec.org/advisories/RUSTSEC-2025-0004.html

Reproducible: Always

Comment 1 Aoife Moloney 2026-08-17 13:33:21 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.


Note You need to log in before you can comment on or make changes to this bug.