Fedora 46 : baresip / libre (2026-b8539090fe)

high Nessus Plugin ID 362869

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 46 host has packages installed that are affected by a vulnerability as referenced in the FEDORA-2026-b8539090fe advisory.

# Baresip v4.12.0 (2026-09-30)
- Feature: Send Custom `X-Headers` on Outbound Calls
- audio: thread-safe usage of psize and ptime in `tx_thread()`
- jbuf: safer `jbuf_set_id`
- audio: add mutex lock for aubuf statistics
- test: add testing of peerconn and vidfilt
- audio: fix format name in ausrc format mismatch warning
- ci: remove brew fdk-aac package (discontinued)
- test: fix peerconn and vidfilt
- cmake: use variable for libdir `libbaresip.pc.in`
- aureceiver: stats cleanup
- rtprecv: tiny cleanup for startup
- rtprecv: add stop flag fixes race condition
- auresamp: alloc for implicit format conversion
- aureceiver: fix decoder sample format and cleanup
- audio: use `RE_ATOMIC` for muted flag
- gst,play: fix err handling

# libre v4.12.0 (2026-09-30)
- [OOB write in AV1 DD decoder template_fdiffs() via unbounded while loop](https://github.com/baresip/re/security/advisories/GHSA-rp4v-6hwc-3w8j)
- [TLS certificate identity check is skipped when the peer is addressed by IP literal: any CA-issued cert is accepted and reported as verified](https://github.com/baresip/re/security/advisories/GHSA-7h33-mhw5-7pwr)
- json,odict: optimize memory and lookup performance
- sys: add `sys_exec`, `sys_texec` and `sys_cexec` (UNIX only)
- sip/transp: verify WSS server identity against the target host
- fmt/pl: optimize `pl_strstr`, `pl_strchr` and `pl_strrchr`
- cmake: use variable for libdir in `libbaresip.pc.in`
- sipreg/sipreg_unregister: call response handler on error
- tls,test: add strict IP-literal SAN TLS verification (no SNI)
- dd: implement out of bound checks
- base64: fix not detected `base64_decode` olen overflow
- httpauth/digest: fix MD5 default hash handler

Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected baresip and / or libre packages.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2026-b8539090fe

Plugin Details

Severity: High

ID: 362869

File Name: fedora_2026-b8539090fe.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:46, p-cpe:/a:fedoraproject:fedora:baresip, p-cpe:/a:fedoraproject:fedora:libre

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 10/3/2026

Vulnerability Publication Date: 10/3/2026

Reference Information