Описание
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| cargo | removed | package | ||
| cargo | no-dsa | bookworm | package | |
| cargo | postponed | bullseye | package | |
| rust-cargo | fixed | 0.91.0-3 | package | |
| rust-cargo | no-dsa | trixie | package | |
| rust-cargo | no-dsa | bookworm | package | |
| rust-cargo | postponed | bullseye | package | |
| rustc | fixed | 1.95.0+dfsg1-2 | package | |
| rustc | no-dsa | trixie | package | |
| rustc | no-dsa | bookworm | package | |
| rustc | postponed | bullseye | package |
Примечания
https://groups.google.com/g/rustlang-security-announcements/c/IB74S7Yksg8
https://blog.rust-lang.org/2026/05/25/cve-2026-5223/
https://github.com/rust-lang/cargo/commit/285cebf58911eca5b7f177f5d0b1c53e1f646577
EPSS
Связанные уязвимости
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
Crates in third party registries can override the cached source of other crates
Cargo crates in third party registries can override the cached source of other crates
EPSS