CVE-2024-52815
Publication date 3 December 2024
Last updated 8 April 2025
Ubuntu priority
Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user’s /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.
Status
Package | Ubuntu Release | Status |
---|---|---|
matrix-synapse | 24.10 oracular |
Vulnerable, fix deferred
|
24.04 LTS noble |
Vulnerable, fix deferred
|
|
22.04 LTS jammy |
Vulnerable, fix deferred
|
|
20.04 LTS focal |
Vulnerable, fix deferred
|
|
18.04 LTS bionic |
Vulnerable, fix deferred
|
Notes
john-breton
As of 7/4/2025 no patch for this CVE exists. It may be possible to extract the fix from 1.120.1 source, but such an undertaking would require significant effort.