Bug 35179 - coturn new security issue CVE-2026-27624
Summary: coturn new security issue CVE-2026-27624
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2026-03-05 15:35 CET by Nicolas Salguero
Modified: 2026-03-09 18:50 CET (History)
3 users (show)

See Also:
Source RPM: coturn-4.6.2-1.mga9.src.rpm
CVE: CVE-2026-27624
Status comment:
herman.viaene: test_passed_mga9_64+


Attachments

Comment 1 Nicolas Salguero 2026-03-05 15:36:33 CET
Fixed by https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b (4.9.0)

Flags: (none) => affects_mga9+
CVE: (none) => CVE-2026-27624
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => coturn-4.8.0-1.mga10.src.rpm, coturn-4.6.2-1.mga9.src.rpm
Status comment: (none) => Fixed upstream in 4.9.0 and patch available from upstream

Comment 2 Nicolas Salguero 2026-03-05 15:46:23 CET
For Cauldron, I asked for a freeze move.


Suggested advisory:
========================

The updated package fixes a security vulnerability:

IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL. (CVE-2026-27624)

References:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/37LHFMZ3OPUJRL3DZ3WVCJ7FO62HMVUT/
========================

Updated package in core/updates_testing:
========================
coturn-4.6.2-1.1.mga9

from SRPM:
coturn-4.6.2-1.1.mga9.src.rpm

Status: NEW => ASSIGNED
Version: Cauldron => 9
Source RPM: coturn-4.8.0-1.mga10.src.rpm, coturn-4.6.2-1.mga9.src.rpm => coturn-4.6.2-1.mga9.src.rpm
Status comment: Fixed upstream in 4.9.0 and patch available from upstream => (none)
Flags: affects_mga9+ => (none)
Assignee: bugsquad => qa-bugs
Whiteboard: MGA9TOO => (none)

Comment 3 Herman Viaene 2026-03-06 10:39:49 CET
MGA9-64 server Plasma Wayland on Compaq H000SB
No installation issues.
Ref bug 26879

# systemctl -l status turnserver
○ turnserver.service - coturn
     Loaded: loaded (/usr/lib/systemd/system/turnserver.service; disabled; preset: disabled)
     Active: inactive (dead)
       Docs: man:coturn(1)
             man:turnadmin(1)
             man:turnserver(1)
# systemctl start turnserver
# systemctl -l status turnserver
● turnserver.service - coturn
     Loaded: loaded (/usr/lib/systemd/system/turnserver.service; disabled; preset: disabled)
     Active: active (running) since Fri 2026-03-06 10:33:35 CET; 17s ago
       Docs: man:coturn(1)
             man:turnadmin(1)
             man:turnserver(1)
   Main PID: 18481 (turnserver)
      Tasks: 9 (limit: 8805)
     Memory: 5.0M
        CPU: 11.567s
     CGroup: /system.slice/turnserver.service
             └─18481 /usr/bin/turnserver -c /etc/turnserver/turnserver.conf

Mar 06 10:33:35 mach3.hviaene.thuis systemd[1]: Starting turnserver.service...
Mar 06 10:33:35 mach3.hviaene.thuis systemd[1]: Started turnserver.service.

$ netstat -nl | grep 3478
tcp        0      0 192.168.2.3:3478        0.0.0.0:*               LISTEN     
tcp        0      0 192.168.2.3:3478        0.0.0.0:*               LISTEN     
tcp        0      0 192.168.2.3:3478        0.0.0.0:*               LISTEN     
tcp        0      0 192.168.2.3:3478        0.0.0.0:*               LISTEN     
tcp        0      0 127.0.0.1:3478          0.0.0.0:*               LISTEN     
tcp        0      0 127.0.0.1:3478          0.0.0.0:*               LISTEN     
tcp        0      0 127.0.0.1:3478          0.0.0.0:*               LISTEN     
tcp        0      0 127.0.0.1:3478          0.0.0.0:*               LISTEN     
tcp6       0      0 ::1:3478                :::*                    LISTEN     
tcp6       0      0 ::1:3478                :::*                    LISTEN     
tcp6       0      0 ::1:3478                :::*                    LISTEN     
tcp6       0      0 ::1:3478                :::*                    LISTEN     
tcp6       0      0 fd00::baee:65ff:fe:3478 :::*                    LISTEN     
tcp6       0      0 fd00::baee:65ff:fe:3478 :::*                    LISTEN     
tcp6       0      0 fd00::baee:65ff:fe:3478 :::*                    LISTEN     
tcp6       0      0 fd00::baee:65ff:fe:3478 :::*                    LISTEN     
udp        0      0 192.168.2.3:3478        0.0.0.0:*                          
udp        0      0 192.168.2.3:3478        0.0.0.0:*                          
udp        0      0 192.168.2.3:3478        0.0.0.0:*                          
udp        0      0 192.168.2.3:3478        0.0.0.0:*                          
udp        0      0 127.0.0.1:3478          0.0.0.0:*                          
udp        0      0 127.0.0.1:3478          0.0.0.0:*                          
udp        0      0 127.0.0.1:3478          0.0.0.0:*                          
udp        0      0 127.0.0.1:3478          0.0.0.0:*                          
udp6       0      0 ::1:3478                :::*                               
udp6       0      0 ::1:3478                :::*                               
udp6       0      0 ::1:3478                :::*                               
udp6       0      0 ::1:3478                :::*                               
udp6       0      0 fd00::baee:65ff:fe:3478 :::*                               
udp6       0      0 fd00::baee:65ff:fe:3478 :::*                               
udp6       0      0 fd00::baee:65ff:fe:3478 :::*                               
udp6       0      0 fd00::baee:65ff:fe:3478 :::*                               
[tester9@mach3 ~]$ telnet 192.168.2.3 3478
Trying 192.168.2.3...
Connected to mach3.hviaene.thuis (192.168.2.3).
Escape character is '^]'.

OK to go.

Flags: (none) => test_passed_mga9_64+
Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

katnatek 2026-03-07 02:30:26 CET

CC: (none) => andrewsfarm
Keywords: (none) => advisory

Comment 4 Thomas Andrews 2026-03-07 04:24:57 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 5 Mageia Robot 2026-03-09 18:50:09 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0051.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.