Hi all,
I am planning to retire the syncthing package from EPEL 9 and 8 in ~one week (approx. July 14) according to the policy for retirements for "security reasons", as previously discussed here: https://lists.fedoraproject.org/archives/list/epel-devel@lists.fedoraproject...
More details reproduced below.
Fabio
--------------------------------------------------------------------------------
The syncthing packages in EPEL 9 and 8 are currently affected by the following security-related bugs:
- CVE-2025-47906: syncthing: Unexpected paths returned from LookPath in os/exec - CVE-2025-58189: go crypto/tls ALPN negotiation error contains attacker controlled information - CVE-2025-61723: encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem - CVE-2025-58185: encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 - CVE-2025-58188: crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 - CVE-2025-58183: golang: archive/tar: Unbounded allocation when parsing GNU sparse map
(see also RHBZ# 2399028, 2407565, 2408972, 2409019, 2409915, 2409966, 2410854, 2410899, and potentially more ...)
The packages currently shipped in EPEL 9 and 8 cannot be rebuilt with newer golang compilers due to compiler changes making the package fail to build, and it cannot be updated to newer versions due to RHEL 9 and 8 shipping sqlite that is so old that it doesn't support the features needed by syncthing v2.
Fabio
epel-devel@lists.fedoraproject.org