We believe that the bug you reported is fixed in the latest version of
coturn, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1145022@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Guillem Jover <gjover@sipwise.com> (supplier of updated coturn package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 14:51:09 +0200
Source: coturn
Architecture: source
Version: 4.18.0-1
Distribution: unstable
Urgency: high
Maintainer: Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>
Changed-By: Guillem Jover <gjover@sipwise.com>
Closes: 998680 1137305 1142829 1144385 1145022 1149725
Changes:
coturn (4.18.0-1) unstable; urgency=high
.
* Team upload.
* New upstream version 4.18.0. (Closes: #1149725)
- Fixes CVE-2026-68555. In 4.15.0, an authenticated TURN user can
repeatedly resume one allocation from fresh UDP 5-tuples without
completing a handoff when the server enables --mobility.
mobile_begin_transition() in src/server/ns_turn_server.c disarms each
new session's allocation timeout and overwrites the allocation's single
mobile_pending_resume link, leaving earlier pending sessions unreachable
by the cleanup path, while copy_auth_parameters() ignores inc_quota()
failure. The attacker can therefore retain unbounded server-side sessions
and exhaust process memory even when --user-quota=1 is configured.
(Closes: #1145022)
- Fixes CVE-2026-73213. Prior to 4.16.0, addr_less_eq() in
src/client/ns_turn_ioaddr.c uses a component-wise comparison for native
IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated
TURN client to relay to an IPv6 peer that is numerically within a
configured non-prefix-aligned denied-peer-ip range but is classified as
outside it.
- Fixes CVE-2026-73214. Prior to 4.16.0, dtls_server_input_handler() and
create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c
retain OpenSSL dtls1_reassemble_fragment() state for a 35-byte fragmented
ClientHello declaring a 650,000-byte handshake before cookie validation,
allowing an unauthenticated remote sender using fresh UDP tuples to
exhaust memory without TURN credentials, a completed handshake, a valid
cookie, or source spoofing.
- Fixes CVE-2026-73215. Prior to 4.17.0, turnports_allocate_even() in
src/apps/relay/turn_ports.c marks the unused odd sibling port as
TPS_TAKEN_ODD for an EVEN-PORT Allocate request with reservation bit
R=0 even though no RTCP socket will release it, allowing an
authenticated client to permanently exhaust the relay port pool and
cause subsequent allocations to fail with STUN error 508.
- Fixes CVE-2026-73216. Prior to 4.17.0, shutdown_client_connection() in
src/server/ns_turn_server.c prematurely calls dec_quota() and releases
bandwidth accounting during the first-stage close of a mobility-enabled
allocation while preserving the allocation, relay socket, session, and
mobility ticket, allowing an authenticated client to bypass --user-quota
and --total-quota and exhaust relay ports.
(Closes: #1144385)
- Refresh patch.
* Remove C style code comment prefixes from License field values.
* Run wrap-and-sort -ast.
* Remove «Rules-Requires-Root: no», which is now the default.
* Remove «Priority: optional», which is now the default.
* Replace boilerplate header from maintainer scripts with man page references.
* Switch setup test to be a fragment file to be sourced.
Based on a patch by Pavel Punsky <eakraly@users.noreply.github.com>.
(Closes: #1142829)
* Switch from After=network.target to After/Requires=network-online.target.
(Closes: #998680)
* Switch build-dependencies from mysql-defaults to mariadb.
(Closes: #1137305)
* Add a debian/.gitignore file.
* Comment out DH_VERBOSE variable.
* Remove exported empty DH_OPTIONS variable.
* Terminate multi-line CLI options with an EOC comment.
* Bump Standards-Version to 4.7.4.
Checksums-Sha1:
dd6d5ffcd1252161b63f3a8d082dae8190287b41 2337 coturn_4.18.0-1.dsc
e2384a3933c9f6d2804e6ac832a6bc908ee24f06 578044 coturn_4.18.0.orig.tar.xz
e3e06e8f49c17e973b4edc270f0c91c67cfad8db 15648 coturn_4.18.0-1.debian.tar.xz
2ea1c08fa573a0a8f2c87cf0792a37904c25b752 7181 coturn_4.18.0-1_amd64.buildinfo
Checksums-Sha256:
eed616b4af482819fe78c9122b72b631d18dd7768b6bc61d9db96bb69573be26 2337 coturn_4.18.0-1.dsc
4e1c4cfa758f7c862852dadbdd492c3c1293c16b25bbc81f6200aea7cc20456b 578044 coturn_4.18.0.orig.tar.xz
381684cae3aaa91ddb4701fa906e838f820e80d15ba1cf7ab183c584d5e14f5c 15648 coturn_4.18.0-1.debian.tar.xz
b545585e3d22f5a89230b2e0199de207e55c80b4abc6e8717f169fbbda2894c8 7181 coturn_4.18.0-1_amd64.buildinfo
Files:
128e58b76c974fa04aae15ab26d525ab 2337 net optional coturn_4.18.0-1.dsc
3b342199d4e0d57e7fe6619a708fdd1b 578044 net optional coturn_4.18.0.orig.tar.xz
395412ebf87f51ca4093f3bffc0587d8 15648 net optional coturn_4.18.0-1.debian.tar.xz
4a454c10822cb6cf2a2597ff2dab9f3b 7181 net optional coturn_4.18.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
wsG7BAEBCgBvBYJqxPLPCRC5cr8+pK5Xo0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcmdC6IPd0fr5lbJLyInFj1krAaTGtdr7PUOOGbShQp6a
AxYhBE8+dPQ2BQwQ9WlldLlyvz6krlejAADHMxAAxkXAX3sjzjqJOqkSpXDCqwjt
TCXgpPAcvXlmzK3y8N7XOtbHKg4Xs+YwBV86vHtIyENtUdzXobOWs9l+DPIBB78V
L8GfPYbPNUhAnML5WxYd9IgYCsrXEbJrhRrZC1u4pJRopdaktAP3WWqnyvUub964
YCynkNRwaE8TTaoyQZNdMaxlhCpQBWcGufDElhQlpn8qmNwklWcFbhWwBpSJN8rs
ENg+/cOTbWvYUexa4tWnebm10rIpxPVR5ymSWH6BjekYW/JeU0VOsxiNifTFxHKz
TQrEL8K9T6TcqzD5eLvwHHLwxWqHbkGC1eCMcLlZf4rQcU2XWDScq/FQ4afKyDjK
w87AIxdjNYE08bUowUvS2hIEIfTTVHCWkinlfjChooO2I0v74+Uq8RoXv2kiLOFp
huU76m2D74BOjiWBM21/vE2/IZNzycKJVnb7IDDiDMpLRTXfnvxA2IwPrLvJ/jCD
//ghM4YyDLXESBm7AGG81cLbKz7aSLXhawjGdgcKrbsZg4X4HAnxIY4ByDj7kxSo
7ALSudma16QZCfFFhCdpT4WrM/n6Aw/LryYzNPX+0xp8ezRMP5bdAZoqJl8gAdQR
XfXzWfsrxvc+n7y8kfeXVZifSLOjczF7tvSv8ibNaOEvdAW4oOXgIBPrQ77y0ICG
FgZaCmFVEN+VlRU/IlU=
=fnam
-----END PGP SIGNATURE-----