PT-2024-40386 · Libolm+3 · Libolm+3

Published

2024-09-03

·

Updated

2024-09-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions olm-sys (affected versions not specified) olm-rs (affected versions not specified)
Description The Matrix Foundation has officially deprecated the libolm library due to several publicly disclosed cryptographic vulnerabilities. As a result, olm-sys, a thin wrapper around libolm, is also deprecated and potentially vulnerable. Users are encouraged to switch to vodozemac, the successor effort to libolm, written in Rust.
Recommendations For olm-sys, consider switching to vodozemac as soon as possible. For olm-rs, consider switching to vodozemac as soon as possible. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

GHSA-P2Q9-36VW-C468

Affected Products

Libolm
Olm-Rs
Olm-Sys
Vodozemac