Fedora 44 : coturn (2026-8856c5be6f)

high Nessus Plugin ID 331602

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 44 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2026-8856c5be6f advisory.

# Coturn 4.15.0

## Security
- **Ignore STUN attributes after MESSAGE-INTEGRITY** (GHSA-5538-7cxj-5jcc). Per RFC 8489 9 / RFC 5389 15.4, attributes following MESSAGE-INTEGRITY (other than FINGERPRINT) must be ignored, but coturn processed the full attribute list. This also fixes an interop bug where an RFC 8489 client sending MESSAGE-INTEGRITY-SHA256 after MESSAGE-INTEGRITY was wrongly answered with error 420.
- **Bind mobility session-resume to the original allocation owner** a MOBILITY-TICKET resume is now only accepted from the user that created the allocation.
- **Reject ACME requests via signed 400 response** instead of silently dropping them.
- Reset the reused UDP receive-buffer offset in the DTLS listener.
- Zeroed channel-data padding in `stun_init_channel_message_str` so uninitialized stack bytes never reach the wire.
- Fixed a `uint16_t` truncation overflow when computing STUN message length.
- Fixed an off-by-one write past the realm buffer in `redis_list_admin_users`.
- Fixed a `size_t` underflow in the telnet (CLI) `_process` data emit and bounded MSSP subnegotiation parsing to the buffer end.
- NULL-terminated the HTTP request buffer before it is logged verbatim; switched `apputils.c` to bounded `snprintf`.

## New features
- **RFC 8016 graceful dual-5-tuple mobility handoff**. A MOBILITY-TICKET resume no longer hard-switches the allocation at REFRESH time. The server now does a make-before-break transition: peerclient traffic stays on the old 5-tuple until the client's first packet arrives on the new one, and only then is the old socket discarded.
- `--drain-min-allocations` a shutdown threshold for drain mode: the server exits once the live allocation count falls to the configured value instead of waiting for zero.
- `--log-min-level` (`log_min_level` in the config file) a real minimum-log-level filter, since `-v`/`--verbose` had little effect on turnserver logging.
- **Alternate-server TCP/UDP distinction** alternate servers are now tracked per transport, so TCP and UDP clients can be redirected to different alternate servers.
- **Fail-fast allocation wrappers** all heap allocation in coturn-owned code goes through `turn_malloc`/`turn_calloc`/`turn_realloc`/`turn_strdup`, which log the call site and abort on OOM rather than risking NULL-dereference or silent degradation in a long-running server.

## Reliability and correctness fixes
- Fixed the remaining misaligned wire-buffer accesses and added alignment-safe `turn_read_u16`/`u32`/`u64` / `turn_write_*` helpers misaligned reads of STUN attribute values were undefined behavior and a SIGBUS on strict-alignment targets.
- Fixed `uint32_t` counter wraparound in the relay port allocator.
- Worker threads are now joined on shutdown, fixing an exit-time OpenSSL race; OpenSSL atexit cleanup is disabled in turnserver.
- Released the alternate-server list mutex when `del_alt_server` removes the last entry, fixing a deadlock.
- `setgroups` is no longer called unconditionally in mainrelay, fixing startup under environments where it's not permitted.
- Freed `EVP_CIPHER_CTX` on error paths in the OAuth GCM encode/decode and avoided leaks on realloc failure in TCP relay allocation.
- Cast to `unsigned char` before `isspace()` in config-file parsing.
- Log an explicit error when a configured `tls-listening-port` cannot start.
- Autotools build now detects `hiredis_ssl`, enabling Redis TLS in the `./configure` build.

## Metrics
- Every STUN Binding response is now counted in the Prometheus metrics.

## Client utilities
- `turnutils_uclient` now sends the SNI host name on TLS connections.
- heap-allocates its STUN message buffers instead of using large stack buffers.


Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected coturn package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2026-8856c5be6f

Plugin Details

Severity: High

ID: 331602

File Name: fedora_2026-8856c5be6f.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/2/2026

Updated: 8/2/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:44, p-cpe:/a:fedoraproject:fedora:coturn

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/24/2026

Vulnerability Publication Date: 7/24/2026

Reference Information