Denis Kasak discovered that Olm was not verifying the length of input being processed by the olmpkdecrypt module, which introduced a stack-based buffer overflow vulnerability to the library. An attacker could use this to cause a denial of service (application crash) or possibly execute arbitrary code.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_version": "3.1.3+dfsg-2ubuntu0.1~esm1", "binary_name": "libolm-dev" }, { "binary_version": "3.1.3+dfsg-2ubuntu0.1~esm1", "binary_name": "libolm3" }, { "binary_version": "3.1.3+dfsg-2ubuntu0.1~esm1", "binary_name": "libolm3-dbgsym" }, { "binary_version": "3.1.3+dfsg-2ubuntu0.1~esm1", "binary_name": "python3-olm" }, { "binary_version": "3.1.3+dfsg-2ubuntu0.1~esm1", "binary_name": "python3-olm-dbgsym" } ] }