Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5223

Опубликовано: 25 мая 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is medium for users of third-party registries. Users of crates.io are not affected, as crates.io forbids uploading crates containing any symlink.

A flaw was found in Cargo. When processing crate tarballs from third-party registries, Cargo mishandled symbolic links (symlinks) embedded within these archives. This vulnerability enables a malicious crate to overwrite the source code of another crate originating from the same registry. Such an action could lead to unauthorized modification of software components, potentially introducing security risks or operational disruptions.

Отчет

This Moderate vulnerability in Cargo arises from improper handling of symlinks within crate tarballs downloaded from third-party registries. An attacker could exploit this by publishing a malicious crate containing symlinks, leading to the overwrite of source code from other crates in the same registry. Red Hat customers using crates.io are not affected, as crates.io prohibits symlinks in uploaded crates.

Меры по смягчению последствий

To mitigate this issue, avoid using untrusted third-party Cargo registries. If third-party registries are necessary, ensure they enforce strict policies against symlinks in crate tarballs and verify the integrity of downloaded crates. No direct configuration or operational workaround is available within Cargo itself to prevent this specific symlink mishandling when using vulnerable third-party registries.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9gooseFix deferred
Red Hat Enterprise Linux 9greenboot-rsFix deferred
Red Hat Enterprise Linux 9rustFix deferred
Red Hat Hardened Imagesrust-main-1.97.1-1.1.hum1FixedRHSA-2026:4292321.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2481158cargo: Cargo: Source code overwrite due to symlink mishandling in third-party registries

EPSS

Процентиль: 21%
0.00294
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

CVSS3: 5.3
nvd
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

msrc
2 месяца назад

Crates in third party registries can override the cached source of other crates

CVSS3: 5.3
debian
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded ...

github
около 1 месяца назад

Cargo crates in third party registries can override the cached source of other crates

EPSS

Процентиль: 21%
0.00294
Низкий

5.3 Medium

CVSS3