CVE-2023-45129

Publication date 10 October 2023

Last updated 26 August 2025


Ubuntu priority

Cvss 3 Severity Score

4.9 · Medium

Score breakdown

Description

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.

Read the notes from the security team

Status

Package Ubuntu Release Status
matrix-synapse 24.10 oracular
Not affected
24.04 LTS noble
Not affected
23.10 mantic Ignored end of life, was needs-triage
23.04 lunar Ignored end of life, was needs-triage
22.04 LTS jammy Ignored patch infeasible
20.04 LTS focal Ignored end of standard support, was ignored [patch infeasible]
18.04 LTS bionic Ignored end of standard support
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Notes


john-breton

Both rust/src and stubs/synapses (which the patch targets) DNE in bionic-jammy. Without that functionality, patching is infeasible, and those modules require significant revisions to even get to function with the older versions.

Severity score breakdown

CVSS version: CVSS v3.0

Base score 4.9 · Medium

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H


Access our resources on patching vulnerabilities