Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-05136

Опубликовано: 05 фев. 2026
Источник: fstec
CVSS3: 5.8
CVSS2: 4.9
EPSS Низкий

Описание

Уязвимость модуля для работы с датой и временем time языка программирования Rust связана с выходом операции за границы буфера в памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Red Hat Inc.
АО «СберТех»
The Rust Foundation
ООО «Пикодата»

Наименование ПО

OpenShift Container Platform
Red Hat Quay
Red Hat Satellite
OpenShift Dev Spaces
Logging subsystem for Red Hat OpenShift
OpenShift AI
Red Hat OpenShift Lightspeed
Red Hat Trusted Artifact Signer
Confidential Compute Attestation
Platform V SberLinux OS Server
Red Hat Connectivity Link
Red Hat Enterprise Linux AI
Ansible Automation Platform
Lightspeed Core
Pen Drive Powered by Red Hat Lightspeed
Red Hat OpenShift Update Service
Rust
Picodata

Версия ПО

4 (OpenShift Container Platform)
3 (Red Hat Quay)
6 (Red Hat Satellite)
- (OpenShift Dev Spaces)
- (Logging subsystem for Red Hat OpenShift)
- (OpenShift AI)
- (Red Hat OpenShift Lightspeed)
- (Red Hat Trusted Artifact Signer)
- (Confidential Compute Attestation)
9.2.0-fstec (Platform V SberLinux OS Server)
1 (Red Hat Connectivity Link)
3 (Red Hat Enterprise Linux AI)
2 (Ansible Automation Platform)
- (Lightspeed Core)
- (Pen Drive Powered by Red Hat Lightspeed)
- (Red Hat OpenShift Update Service)
от 0.3.6 до 0.3.47 (Rust)
до 9.2.0-fstec (Platform V SberLinux OS Server)
25.2.2 (Picodata)

Тип ПО

Прикладное ПО информационных систем
ПО для разработки ИИ
Операционная система
СУБД

Операционные системы и аппаратные платформы

АО «СберТех» Platform V SberLinux OS Server 9.2.0-fstec
Red Hat Inc. Red Hat Enterprise Linux AI 3
АО «СберТех» Platform V SberLinux OS Server до 9.2.0-fstec

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4,9)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,8)
Средний уровень опасности (оценка CVSS 4.0 составляет 6,8)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://github.com/time-rs/time/security/advisories/GHSA-r6v5-fh4h-64xc
Для Platform V SberLinux OS Server:
Обновление операционной системы до версии 9.2.2-fstec
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-25727
Для Picodata:
Обновление программного обеспечения до версии 26.1.1 и выше
Компенсирующие меры:
- минимизация пользовательских привилегий;
- отключение/удаление неиспользуемых учётных записей пользователей;
- контроль журналов аудита кластера для отслеживания попыток эксплуатации уязвимости.
Для Platform V SberLinux OS Server:
Обновление операционной системы до версии 9.2.2-fstec или выше

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 21%
0.00291
Низкий

5.8 Medium

CVSS3

4.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
6 месяцев назад

time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.

CVSS3: 5.9
redhat
6 месяцев назад

time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.

CVSS3: 6.5
nvd
6 месяцев назад

time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.

msrc
2 дня назад

time affected by a stack exhaustion denial of service attack

CVSS3: 6.5
debian
6 месяцев назад

time provides date and time handling in Rust. From 0.3.6 to before 0.3 ...

EPSS

Процентиль: 21%
0.00291
Низкий

5.8 Medium

CVSS3

4.9 Medium

CVSS2