Views
16

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

USN-8724-1 updates `rabbitmq-c` for Ubuntu 22.04 LTS (jammy) to address multiple security issues, including credential exposure, denial of service, information disclosure, and possible code execution. The affected packages are `amqp-tools`, `librabbitmq-dev`, and `librabbitmq4`.

Update Details

Security

  • Credentials could be exposed through the process list because the command-line tools only accepted credentials on the command line. (CVE-2023-35789)
  • Incorrect AMQP frame length calculation could cause a size_t underflow, leading to a crash or possible sensitive information exposure. (CVE-2026-44235)
  • Improper frame size validation during the AMQP login handshake could allow a heap buffer overflow, causing denial of service or possible arbitrary code execution. (CVE-2026-44236)
  • Incorrect validation of decoded bytes field lengths could cause an integer overflow in a bounds check on 32-bit systems, leading to out-of-bounds reads, denial of service, or information disclosure. (CVE-2026-59986)
  • Missing validation of body fragment length in amqp_send_frame() could allow a heap buffer overflow, causing denial of service or possible arbitrary code execution. (CVE-2026-61547)

Hints

  • A standard system update installs the fixes.
  • For Ubuntu 22.04 LTS (jammy), update amqp-tools to 0.10.0-1ubuntu2.2, librabbitmq-dev to 0.10.0-1ubuntu2.2, and librabbitmq4 to 0.10.0-1ubuntu2.2.

Product Information

Vendor: Canonical

Product: Ubuntu Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 22.04 LTS (Jammy Jellyfish)

Version: 0.10.0-1ubuntu2.2

Vendor release date: Sep 3, 2026

Original release notes: View on vendor site

Published on updatealert.io: Sep 4, 2026

Description: Server operating system for Linux infrastructure and workloads.