Skip to content

dep(components): bump libp2p-quic 0.13.0 -> 0.13.1 for CVE-2026-61544 (v2.2.3) - #153

Open
alexwood wants to merge 1 commit into
release-op-reth/v2.2.3from
cve/CVE-2026-61544-libp2p-quic-v2.2.3
Open

alexwood wants to merge 1 commit into
release-op-reth/v2.2.3from
cve/CVE-2026-61544-libp2p-quic-v2.2.3

Conversation

@alexwood

Copy link
Copy Markdown

Description

CVE patch for HIGH CVE-2026-61544 (GHSA-5hq8-qhww-jm7q): remote panic in libp2p-quic via a certificate-expiry race during QUIC handshake. Companion forward-port of #152 so the fix is not lost when the kaleido-node-op-reth pin advances from release-op-reth/v2.2.0 to v2.2.3.

Details

  • CVE patch
  • Fork sync
  • Routine dependency bump
Crate libp2p-quic
From 0.13.0
To 0.13.1
Advisory CVE-2026-61544 / GHSA-5hq8-qhww-jm7q
Severity HIGH

Same lockfile-only change as #152: cargo update -p libp2p-quic --precise 0.13.1 in rust/. libp2p 0.56.0 constrains libp2p-quic ^0.13.0, so 0.13.1 is the compatible patched release.

The shipping image currently builds release-op-reth/v2.2.0 (#152). This PR is the forward-port only.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant