CVE-2024-52815

Publication date 3 December 2024

Last updated 8 April 2025


Ubuntu priority

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user’s /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.

Read the notes from the security team

Status

Package Ubuntu Release Status
matrix-synapse 24.10 oracular
Vulnerable, fix deferred
24.04 LTS noble
Vulnerable, fix deferred
22.04 LTS jammy
Vulnerable, fix deferred
20.04 LTS focal
Vulnerable, fix deferred
18.04 LTS bionic
Vulnerable, fix deferred

Notes


john-breton

As of 7/4/2025 no patch for this CVE exists. It may be possible to extract the fix from 1.120.1 source, but such an undertaking would require significant effort.