Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olmpkdecrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_version": "3.1.3+dfsg-2ubuntu0.1~esm1", "binary_name": "libolm-dev" }, { "binary_version": "3.1.3+dfsg-2ubuntu0.1~esm1", "binary_name": "libolm3" }, { "binary_version": "3.1.3+dfsg-2ubuntu0.1~esm1", "binary_name": "libolm3-dbgsym" }, { "binary_version": "3.1.3+dfsg-2ubuntu0.1~esm1", "binary_name": "python3-olm" }, { "binary_version": "3.1.3+dfsg-2ubuntu0.1~esm1", "binary_name": "python3-olm-dbgsym" } ], "ubuntu_priority": "medium" }