Skip to content

dev-c853881

Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 11 Sep 00:29
· 3 commits to main since this release

πŸ“¦ synapse β€” v0.0.0-dev+c853881

Release type: prerelease β€’ Commit: c853881

Security: πŸ›‘οΈ ❌ Critical β€” 7 critical and 134 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/synapse dev-c853881 latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/synapse dev-c853881 latest-dev
GitHub Container Registry ghcr.io/homelabhd/synapse dev-c853881 latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/synapse

docker pull docker.io/hlhd/synapse@sha256:031573d6ae4b635ae794561dbc2e64d146e77c14ce6f3af1308586335372c096

cr.pcfae.com/hlhd/synapse

docker pull cr.pcfae.com/hlhd/synapse@sha256:031573d6ae4b635ae794561dbc2e64d146e77c14ce6f3af1308586335372c096

ghcr.io/homelabhd/synapse

docker pull ghcr.io/homelabhd/synapse@sha256:031573d6ae4b635ae794561dbc2e64d146e77c14ce6f3af1308586335372c096

Notable Changes

Features

  • image: package a hardened synapse image with s3 media and the antispam hook (SoFMeRight)

Documentation

  • refresh generated badges (stagefreight)
  • drop the decorative emoji from the title (SoFMeRight)
  • follow the org readme structure and document configuration (SoFMeRight)

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) Γ—2

Security

πŸ›‘οΈ ❌ Critical β€” 7 critical and 134 high vulnerabilities detected

Vulnerability details (7 critical, 134 high, 155 medium, 103 low)
Severity CVE Package Installed Fixed Description
Critical CVE-2026-6653 libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3 β€” Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper...
Critical CVE-2026-13221 perl-base 5.40.1-6 β€” Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string...
Critical CVE-2026-42496 perl-base 5.40.1-6 β€” Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 perl-base 5.40.1-6 β€” Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit...
Critical CVE-2025-68121 stdlib v1.24.4 1.24.13, 1.25.7, 1.26.0-rc.3 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may...
Critical GO-2026-4337 stdlib go1.24.4 1.24.13 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may...
Critical CVE-2026-27143 stdlib go1.24.4 1.25.9 Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially...
High CVE-2026-76642 bsdutils 1:2.41.5-0+deb13u1 β€” util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 bsdutils 1:2.41.5-0+deb13u1 β€” The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78409 bsdutils 1:2.41.5-0+deb13u1 β€” The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW...
High CVE-2026-78410 bsdutils 1:2.41.5-0+deb13u1 β€” A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High CVE-2026-12064 curl 8.14.1-2+deb13u4 8.21.0 When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl...
High CVE-2026-8286 curl 8.14.1-2+deb13u4 8.21.0 A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
High CVE-2026-8458 curl 8.14.1-2+deb13u4 8.21.0 libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent...
High CVE-2026-8927 curl 8.14.1-2+deb13u4 8.21.0 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests...
High CVE-2026-41992 gzip 1.13-1 β€” GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single...
High CVE-2026-54369 libacl1 2.3.2-2+b1 β€” acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that...
High CVE-2026-76642 libblkid1 2.41.5-0+deb13u1 β€” util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 libblkid1 2.41.5-0+deb13u1 β€” The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78409 libblkid1 2.41.5-0+deb13u1 β€” The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW...
High CVE-2026-78410 libblkid1 2.41.5-0+deb13u1 β€” A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High CVE-2026-12064 libcurl4t64 8.14.1-2+deb13u4 β€” When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl...
High CVE-2026-8286 libcurl4t64 8.14.1-2+deb13u4 β€” A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
High CVE-2026-8458 libcurl4t64 8.14.1-2+deb13u4 β€” libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent...
High CVE-2026-8927 libcurl4t64 8.14.1-2+deb13u4 β€” When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests...
High CVE-2026-76642 liblastlog2-2 2.41.5-0+deb13u1 β€” util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 liblastlog2-2 2.41.5-0+deb13u1 β€” The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78409 liblastlog2-2 2.41.5-0+deb13u1 β€” The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW...
High CVE-2026-78410 liblastlog2-2 2.41.5-0+deb13u1 β€” A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High CVE-2026-76642 libmount1 2.41.5-0+deb13u1 β€” util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 libmount1 2.41.5-0+deb13u1 β€” The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78409 libmount1 2.41.5-0+deb13u1 β€” The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW...
High CVE-2026-78410 libmount1 2.41.5-0+deb13u1 β€” A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High CVE-2025-69720 libncursesw6 6.5+20250216-2 β€” The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
High CVE-2026-76642 libsmartcols1 2.41.5-0+deb13u1 β€” util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 libsmartcols1 2.41.5-0+deb13u1 β€” The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78409 libsmartcols1 2.41.5-0+deb13u1 β€” The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW...
High CVE-2026-78410 libsmartcols1 2.41.5-0+deb13u1 β€” A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High CVE-2026-11822 libsqlite3-0 3.46.1-7+deb13u1 β€” SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution...
High CVE-2026-11824 libsqlite3-0 3.46.1-7+deb13u1 β€” SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a...
High CVE-2026-58050 libssh2-1t64 1.11.1-1+deb13u1 β€” libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without...
High CVE-2026-16742 libsystemd0 257.13-1~deb13u1 β€” systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
High CVE-2025-69720 libtinfo6 6.5+20250216-2 β€” The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
High CVE-2026-16742 libudev1 257.13-1~deb13u1 β€” systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
High CVE-2026-76642 libuuid1 2.41.5-0+deb13u1 β€” util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 libuuid1 2.41.5-0+deb13u1 β€” The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78409 libuuid1 2.41.5-0+deb13u1 β€” The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW...
High CVE-2026-78410 libuuid1 2.41.5-0+deb13u1 β€” A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High CVE-2026-74860 libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3 β€” libxml2: double-free/UAF in libxml2 Python bindings
High CVE-2026-86140 libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3 β€” In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
High CVE-2026-76642 login 1:4.16.0-2+really2.41.5-0+deb13u1 β€” util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 login 1:4.16.0-2+really2.41.5-0+deb13u1 β€” The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78409 login 1:4.16.0-2+really2.41.5-0+deb13u1 β€” The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW...
High CVE-2026-78410 login 1:4.16.0-2+really2.41.5-0+deb13u1 β€” A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High CVE-2026-76642 mount 2.41.5-0+deb13u1 β€” util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 mount 2.41.5-0+deb13u1 β€” The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78409 mount 2.41.5-0+deb13u1 β€” The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW...
High CVE-2026-78410 mount 2.41.5-0+deb13u1 β€” A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High CVE-2025-69720 ncurses-base 6.5+20250216-2 β€” The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
High CVE-2025-69720 ncurses-bin 6.5+20250216-2 β€” The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
High CVE-2026-42497 perl-base 5.40.1-6 β€” Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without...
High CVE-2026-48962 perl-base 5.40.1-6 β€” IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string...
High CVE-2026-57432 perl-base 5.40.1-6 β€” Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack...
High CVE-2026-57433 perl-base 5.40.1-6 β€” Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and...
High CVE-2026-9538 perl-base 5.40.1-6 β€” Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data...
High CVE-2026-76642 util-linux 2.41.5-0+deb13u1 β€” util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 util-linux 2.41.5-0+deb13u1 β€” The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78409 util-linux 2.41.5-0+deb13u1 β€” The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW...
High CVE-2026-78410 util-linux 2.41.5-0+deb13u1 β€” A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High CVE-2026-42304 Twisted 25.5.0 26.4.0rc2 python-twisted: Twisted: Denial of Service via crafted DNS packets in twisted.names
High CVE-2026-69247 cryptography 46.0.7 50.0.0 python-cryptography: python-cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
High CVE-2026-69249 cryptography 46.0.7 49.0.0 python-cryptography: python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
High GHSA-537c-gmf6-5ccf cryptography 46.0.7 48.0.1 Vulnerable OpenSSL included in cryptography wheels
High CVE-2026-41608 thrift 0.22.0 0.24.0 thrift: Apache Thrift Python bindings: Denial of Service via data amplification
High CVE-2026-43871 thrift 0.22.0 0.24.0 thrift: Apache Thrift: Denial of Service via infinite loop
High CVE-2026-82397 tornado 6.5.7 6.5.8 Tornado is a Python web framework and asynchronous networking library. ...
High CVE-2025-61726 stdlib v1.24.4 1.24.12, 1.25.6 The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size...
High CVE-2025-61729 stdlib v1.24.4 1.24.11, 1.25.5 Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out...
High CVE-2026-25679 stdlib v1.24.4 1.25.8, 1.26.1 url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
High CVE-2026-27145 stdlib v1.24.4 1.25.11, 1.26.4 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries...
High CVE-2026-32280 stdlib v1.24.4 1.25.9, 1.26.2 During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a...
High CVE-2026-32281 stdlib v1.24.4 1.25.9, 1.26.2 Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service...
High CVE-2026-32283 stdlib v1.24.4 1.25.9, 1.26.2 If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources...
High CVE-2026-33811 stdlib v1.24.4 1.25.10, 1.26.3 When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
High CVE-2026-33814 stdlib v1.24.4 1.25.10, 1.26.3 When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
High CVE-2026-33818 stdlib v1.24.4 1.25.13, 1.26.6, 1.27.0-rc.3 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
High CVE-2026-39820 stdlib v1.24.4 1.25.10, 1.26.3 Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
High CVE-2026-39821 stdlib v1.24.4 1.25.13, 1.26.6, 1.27.0-rc.3 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
High CVE-2026-39822 stdlib v1.24.4 1.25.12, 1.26.5, 1.27.0-rc.2 On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /...
High CVE-2026-39836 stdlib v1.24.4 1.25.10, 1.26.3 The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
High CVE-2026-42499 stdlib v1.24.4 1.25.10, 1.26.3 Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
High CVE-2026-42504 stdlib v1.24.4 1.25.11, 1.26.4 Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
High CVE-2026-56853 stdlib v1.24.4 1.25.13, 1.26.6, 1.27.0-rc.3 When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface...
High CVE-2026-56858 stdlib v1.24.4 1.25.13, 1.26.6, 1.27.0-rc.3 Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
High CVE-2026-56859 stdlib v1.24.4 1.25.13, 1.26.6, 1.27.0-rc.3 Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
High CVE-2026-56860 stdlib v1.24.4 1.25.13, 1.26.6, 1.27.0-rc.3 Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high...
High CVE-2026-56862 stdlib v1.24.4 1.25.13, 1.26.6, 1.27.0-rc.3 Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not...
High GO-2026-4341 stdlib go1.24.4 1.24.12 The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size...
High CVE-2025-9086 curl 8.14.1 8.16.0 1. A cookie is set using the secure keyword for https://target 2. curl is redirected to or otherwise made to speak with http://target (same hostname, but using clear text HTTP) using...
High GO-2026-4981 stdlib go1.24.4 1.25.10 When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

... and 299 more of lower severity (see full report in release assets)

---
Full changelog
  • [c853881] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [4d2de19] refresh generated badges (stagefreight)
  • [4e88235] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [1d2a22f] drop the decorative emoji from the title (SoFMeRight)
  • [1c2230d] follow the org readme structure and document configuration (SoFMeRight)
  • [c7ceb60] package a hardened synapse image with s3 media and the antispam hook (SoFMeRight)

Container Images