CVE-2024-53863

Publication date 3 December 2024

Last updated 23 April 2025


Ubuntu priority

Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools like Ghostscript for processing. This significantly expands the attack surface in a historically vulnerable area, presenting a risk that far outweighs the benefit, particularly since these formats are rarely used on the open web or within the Matrix ecosystem. Synapse 1.120.1 addresses the issue by restricting thumbnail generation to images in the following widely used formats: PNG, JPEG, GIF, and WebP. This vulnerability is fixed in 1.120.1.

Read the notes from the security team

Status

Package Ubuntu Release Status
matrix-synapse 24.10 oracular Ignored fix infeasible
24.04 LTS noble Ignored fix infeasible
22.04 LTS jammy
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected

Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

Get Ubuntu Pro

Notes


john-breton

Older verions of matrix-synapse lack the thumbnailer module entirely and as such, are not affected. Noble and oracular are FTBFS and will be ignored due to the infeasibility of providing fixes for the releases.