Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
FEDORA-2026-ff2a96c8de (rabbitmq-server-4.2.9-1.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-ff2a96c8de
Upstream advisory metadata for CVE-2026-44839 (GHSA-fh5r-jpm3-fjwp) is inaccurate. Corrected analysis and the Fedora fix follow. Referenced patch is wrong. The advisory/NVD cite commit 7f54319279d1ece161ae0b4cdc6f0e58a4045eb5 as the patch. That commit is from 2017 ("API to restart a crashed vhost") and introduces the vhost-restart mechanism that is the attack precondition -- it is not a fix. It is present in every 4.0.x and 4.1.x release, including 4.0.9 and the advisory's claimed-fixed 4.1.2, so it cannot be the patch. Fixed-version fields are wrong. - "4.0.13" was never released; the 4.0.x line ends at 4.0.9. - 4.1.2 does not contain the fix, and neither does any 4.1.x release through 4.1.4. Actual fix: commit cfce31ef0510f5c3479415b95b4cb118ecc71f7d ("management: Sanitize vhost names in restart forms", 2025-06-17), first released upstream in 4.2.0. Correct boundary: affected < 4.2.0, fixed in 4.2.0. Fedora status: - f44 and rawhide ship >= 4.2.0 (4.2.x / 4.3.x) and already contain the fix. - f43 ships 4.0.9; as no 4.0.x or 4.1.x release carries the fix, cfce31e has been backported onto 4.0.9. Updated F43 build in progress.
FEDORA-2026-ff2a96c8de has been pushed to the Fedora 44 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-ff2a96c8de` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-ff2a96c8de See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-b29cbdb53f (rabbitmq-server-4.0.9-4.fc43) has been submitted as an update to Fedora 43. https://bodhi.fedoraproject.org/updates/FEDORA-2026-b29cbdb53f
FEDORA-2026-6326bdeab0 has been pushed to the Fedora 44 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-6326bdeab0` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-6326bdeab0 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-b29cbdb53f has been pushed to the Fedora 43 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-b29cbdb53f` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-b29cbdb53f See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-548235ea3b has been pushed to the Fedora 43 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-548235ea3b` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-548235ea3b See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-6326bdeab0 (rabbitmq-server-4.2.9-2.fc44) has been pushed to the Fedora 44 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2026-548235ea3b (rabbitmq-server-4.0.9-5.fc43) has been pushed to the Fedora 43 stable repository. If problem still persists, please make note of it in this bug report.