Bug#1144412: activemq: CVE-2026-59878 CVE-2026-61487
Salvatore Bonaccorso <[email protected]>
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <178673312499.1287561.2498624683884880656.reportbug__36824.5325794973$1786733243$gmane$org@eldamar.lan> |
Source: activemq Version: 5.17.6+dfsg-2 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerabilities were published for activemq. CVE-2026-59878[0]: | Improper Input Validation vulnerability in Apache ActiveMQ AMQP, | Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer | that can reach an exposed AMQP NIO connector can trigger denial-of- | service behavior by sending a frame size value. This cause the NIO | threads to die and if done rapidly enough can lead to exhaustion of | the NIO thread pool denying service to other connections. This issue | affects Apache ActiveMQ AMQP: before 5.19.9, from 6.0.0 before | 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8; | Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8. Users | are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0 which | fixes the issue. CVE-2026-61487[1]: | Improper Authorization vulnerability in Apache ActiveMQ Broker, | Apache ActiveMQ All, Apache ActiveMQ. An authenticated low- | privilege user can bypass a per-destination write ACL by sending to | an ActiveMQ temporary composite destination whose physical name is a | comma-separated composite of real queues. This allows publishing | messages to any of the destinations in the list without proper write | ACL permissions because the authorization check is bypassed due to | the composite destination being marked as temporary. This issue | affects Apache ActiveMQ Broker: before 5.19.9, from 6.0.0 before | 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8; | Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8. Users are | recommended to upgrade to version 5.19.9, 6.2.8 or 6.3.0, which | fixes the issue. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-59878 https://www.cve.org/CVERecord?id=CVE-2026-59878 [1] https://security-tracker.debian.org/tracker/CVE-2026-61487 https://www.cve.org/CVERecord?id=CVE-2026-61487 Regards, Salvatore