UBUNTU-CVE-2024-31208

Source
https://ubuntu.com/security/CVE-2024-31208
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-31208.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2024-31208
Related
Published
2024-04-23T18:15:00Z
Modified
2024-10-15T14:14:09Z
Summary
[none]
Details

Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resulting in a denial of service. Servers in private federations, or those that do not federate, are not affected. Server administrators should upgrade to 1.105.1 or later. Some workarounds are available. One can ban the malicious users or ACL block servers from the rooms and/or leave the room and purge the room using the admin API.

References

Affected packages

Ubuntu:Pro:16.04:LTS / synapse

Package

Name
synapse
Purl
pkg:deb/ubuntu/synapse?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.2.99.1-1
0.2.99.2-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / matrix-synapse

Package

Name
matrix-synapse
Purl
pkg:deb/ubuntu/matrix-synapse?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.19.2+dfsg-6
0.24.0+dfsg-1
0.24.0+dfsg-1ubuntu0.1~esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / synapse

Package

Name
synapse
Purl
pkg:deb/ubuntu/synapse?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.2.99.2-3
0.2.99.3-1
0.2.99.4-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / matrix-synapse

Package

Name
matrix-synapse
Purl
pkg:deb/ubuntu/matrix-synapse?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.3.0-1
1.4.0-1
1.5.0-1
1.5.1-1
1.6.0-1
1.6.1-1
1.7.0-2
1.7.1-1
1.7.2-1
1.7.3-1
1.8.0-1
1.9.0-1
1.9.1-1
1.10.0-1
1.10.0-2
1.11.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / synapse

Package

Name
synapse
Purl
pkg:deb/ubuntu/synapse?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.2.99.4-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / matrix-synapse

Package

Name
matrix-synapse
Purl
pkg:deb/ubuntu/matrix-synapse?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.39.0-1
1.47.0-2
1.47.1-1
1.48.0-1
1.49.0-1
1.49.2-1
1.50.1-1
1.50.2-1
1.51.0-1
1.52.0-1
1.53.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / synapse

Package

Name
synapse
Purl
pkg:deb/ubuntu/synapse?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.2.99.4-3
0.2.99.4-3build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / matrix-synapse

Package

Name
matrix-synapse
Purl
pkg:deb/ubuntu/matrix-synapse?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.100.0-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / synapse

Package

Name
synapse
Purl
pkg:deb/ubuntu/synapse?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.2.99.4-4build2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / matrix-synapse

Package

Name
matrix-synapse
Purl
pkg:deb/ubuntu/matrix-synapse?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.90.0-1
1.100.0-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / synapse

Package

Name
synapse
Purl
pkg:deb/ubuntu/synapse?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.2.99.4-4
0.2.99.4-4build1
0.2.99.4-4build2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}