Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.
bcvk is not affected by this. bcvk links against the system OpenSSL library (via reqwest → native-tls → openssl-sys → system libssl), but only uses stream-based TLS for HTTPS connections (container image fetching and registry interactions). The DTLS code path affected by this CVE is not reachable through bcvk: - No DTLS usage exists anywhere in the codebase - The Rust native-tls crate does not expose OpenSSL's DTLS APIs - No UDP/datagram sockets are created — a prerequisite for DTLS - All network I/O is TCP-based HTTP/1.1 and HTTP/2 via the reqwest HTTP client bcvk will pick up the fixed OpenSSL automatically when the system package is updated; no rebuild or code change is needed on bcvk's side.