🛡️ openSUSE-SU-2023:0391-1 — libtorrent-rasterbar (CVE-2023-30801)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for libtorrent-rasterbar, qbittorrent

This update for libtorrent-rasterbar, qbittorrent fixes the following issues:

Changes in libtorrent-rasterbar:

  • Update to version 2.0.9
  • fix issue with web seed connections when they close and

re-open

  • fallocate() not supported is not a fatal error
  • fix proxying of IPv6 connections via IPv4 proxy
  • treat CGNAT address range as local IPs
  • add stricter checking of piece layers when loading torrents
  • add stricter checking of v1 and v2 hashes being consistent
  • cache failed DNS lookups as well as successful ones
  • add an i2p torrent state to control interactions with clear

swarms

  • fix i2p SAM protocol parsing of quoted messages
  • expose i2p peer destination in peer_info
  • fix i2p tracker announces
  • fix issue with read_piece() stopping torrent on pieces not

yet downloaded

  • improve handling of allow_i2p_mixed setting to work for

magnet links

  • fix web seed request for renamed single-file torrents
  • fix issue where web seeds could disappear from resume data
  • extend save_resume with additional conditional flags
  • fix issue with retrying trackers in tiers > 0
  • fix last_upload and last_download resume data fields to use

posix time

  • improve error messages for no_connect_privileged_ports, by

untangle it from the port filter

  • fix I2P issue introduced in 2.0.0
  • add async tracker status query, post_trackers()
  • add async torrent status query, post_status()
  • support loading version 2 of resume data format
  • fix issue with odd piece sizes
  • add async piece availability query, post_piece_availability()
  • add async download queue query, post_download_queue()
  • add async file_progress query, post_file_progress()
  • add async peer_info query, post_peer_info()
  • Update to version 2.0.8
  • fix uTP streams timing out instead of closing cleanly
  • add write_torrent_file_buf() overload for generating

.torrent files

  • add create_torrent::generate_buf() function to generate into

a buffer

  • fix copy_file when the file ends with a sparse region
  • uTP performance, fix packet loss when sending is stalled
  • fix trackers being stuck after session pause/resume
  • fix bug in hash_picker with empty files
  • uTP performance, prevent premature timeouts/resends
  • add option to not memory map files below a certain size
  • settings_pack now returns default values when queried for

missing settings

  • fix copy_file fall-back when SEEK_HOL/SEEK_DATA is not

supported

  • improve error reporting from file copy and move
  • tweak pad file placement to match reference implementation

(tail-padding)

  • uTP performance, more lenient nagle's algorithm to always

allow one outstanding undersized packet

  • uTP performance, piggy-back held back undersized packet with

ACKs

  • uTP performance, don't send redundant deferred ACKs
  • support incoming SOCKS5 packets with hostnames as source

address, for UDP trackers

  • ignore duplicate network interface change notifications on

linux

  • fix total_want/want accounting when forcing a recheck
  • fix merging metadata with magnet links added on top of

existing torrents

  • add torrent_flag to default all file priorities to

dont_download

  • fix &so= feature in magnet links
  • improve compatibility of SOCKS5 UDP ASSOCIATE
  • fix madvise range for flushing cache in mmap_storage
  • open files with no_cache set in O_SYNC mode
  • Update to version 2.0.7
  • fix issue in use of copy_file_range()
  • avoid open-file race in the file_view_pool
  • fix issue where stop-when-ready would not close files
  • fix issue with duplicate hybrid torrent via separate v1 and

v2 magnet links

  • added new function to load torrent files, load_torrent_*()
  • support sync_file_range()
  • fix issue in write_torrent_file() when file size is exactly

piece size

  • fix file_num_blocks() and file_num_pieces() for empty files
  • add new overload to make_magnet_uri()
  • add missing protocol version to tracker_reply_alert and

tracker_error_alert

  • fix privilege issue with SetFileValidData()
  • add asynchronous overload of torrent_handle::add_piece()
  • default to a single hashing thread, for full checks
  • Fix bug when checking files and the first piece is invalid

Changes in qbittorrent, qbittorrent:

  • Update to version 4.6.2

Bug fixes:

  • Do not apply share limit if the previous one was applied
  • Show Add new torrent dialog on main window screen

Web UI:

  • Fix JS memory leak
  • Disable stdout buffering for qbt-nox

Wayland:

  • Fix parent widget of 'Lock qBittorrent' submenu
  • Also fixes boo#1217677 (CVE-2023-30801, upstream reference

gh#qbittorrent/qBittorrent#19738)

  • Update to version 4.6.1

New features:

  • Add option to enable previous Add new torrent dialog behavior

Fixed bugs:

  • Prevent crash due to race condition when adding magnet link
  • Fix Enter key behavior when add ne

Affected software

openSUSE-SU-2023:0391-1 is recorded against 2 packages.

  • libtorrent-rasterbar (fixed in 2.0.9-bp155.2.3.1)
  • qbittorrent (fixed in 4.6.2-bp155.2.3.1)

Timeline and source

Published on 7 December 2023 and last revised on 7 May 2025. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

lists.opensuse.org (Advisory)
bugzilla.suse.com (Report)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-12-07
Updated 2026-08-20
Modified 2025-05-07
Fix URL N/A

Affected Packages

Software From version Fixed in
libtorrent-rasterbar 2.0.9-bp155.2.3.1
qbittorrent 4.6.2-bp155.2.3.1

Free Vulnerability Check

Is your site affected by openSUSE-SU-2023:0391-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2023:0391-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2023