CVE-2024-53863
Publication date 3 December 2024
Last updated 23 April 2025
Ubuntu priority
Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools like Ghostscript for processing. This significantly expands the attack surface in a historically vulnerable area, presenting a risk that far outweighs the benefit, particularly since these formats are rarely used on the open web or within the Matrix ecosystem. Synapse 1.120.1 addresses the issue by restricting thumbnail generation to images in the following widely used formats: PNG, JPEG, GIF, and WebP. This vulnerability is fixed in 1.120.1.
Status
Package | Ubuntu Release | Status |
---|---|---|
matrix-synapse | 24.10 oracular | Ignored fix infeasible |
24.04 LTS noble | Ignored fix infeasible | |
22.04 LTS jammy |
Fixed 1.53.0-1ubuntu0.1~esm2
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProNotes
john-breton
Older verions of matrix-synapse lack the thumbnailer module entirely and as such, are not affected. Noble and oracular are FTBFS and will be ignored due to the infeasibility of providing fixes for the releases.
References
Related Ubuntu Security Notices (USN)
- USN-7444-1
- Synapse vulnerabilities
- 22 April 2025