VYPR

rpm package

opensuse/aws-efs-utils&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/aws-efs-utils&distro=openSUSE%20Tumbleweed

Vulnerabilities (6)

  • CVE-2026-16318MedJul 21, 2026
    affected < 3.2.0-1.1fixed 3.2.0-1.1

    The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second cal

  • CVE-2026-16317MedJul 21, 2026
    affected < 3.2.0-1.1fixed 3.2.0-1.1

    Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer co

  • CVE-2026-25541HigFeb 4, 2026
    affected < 3.2.0-1.1fixed 3.2.0-1.1

    Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. Whe

  • CVE-2025-55159MedAug 11, 2025
    affected < 2.3.3-1.1fixed 2.3.3-1.1

    slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing access to uninitialized memory. This could lead to undefined behavior or potentia

  • CVE-2022-46174MedDec 28, 2022
    affected < 1.34.5-1.1fixed 1.34.5-1.1

    efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to r

  • CVE-2020-35881CriDec 31, 2020
    affected < 2.2.1-1.1fixed 2.2.1-1.1

    An issue was discovered in the traitobject crate through 2020-06-01 for Rust. It has false expectations about fat pointers, possibly causing memory corruption in, for example, Rust 2.x.