Описание
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is medium for users of third-party registries. Users of crates.io are not affected, as crates.io forbids uploading crates containing any symlink.
A flaw was found in Cargo. When processing crate tarballs from third-party registries, Cargo mishandled symbolic links (symlinks) embedded within these archives. This vulnerability enables a malicious crate to overwrite the source code of another crate originating from the same registry. Such an action could lead to unauthorized modification of software components, potentially introducing security risks or operational disruptions.
Отчет
This Moderate vulnerability in Cargo arises from improper handling of symlinks within crate tarballs downloaded from third-party registries. An attacker could exploit this by publishing a malicious crate containing symlinks, leading to the overwrite of source code from other crates in the same registry. Red Hat customers using crates.io are not affected, as crates.io prohibits symlinks in uploaded crates.
Меры по смягчению последствий
To mitigate this issue, avoid using untrusted third-party Cargo registries. If third-party registries are necessary, ensure they enforce strict policies against symlinks in crate tarballs and verify the integrity of downloaded crates. No direct configuration or operational workaround is available within Cargo itself to prevent this specific symlink mishandling when using vulnerable third-party registries.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 9 | goose | Fix deferred | ||
| Red Hat Enterprise Linux 9 | greenboot-rs | Fix deferred | ||
| Red Hat Enterprise Linux 9 | rust | Fix deferred | ||
| Red Hat Hardened Images | rust-main-1.97.1-1.1.hum1 | Fixed | RHSA-2026:42923 | 21.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
Crates in third party registries can override the cached source of other crates
Cargo incorrectly handled symlinks inside of crate tarballs downloaded ...
Cargo crates in third party registries can override the cached source of other crates
EPSS
5.3 Medium
CVSS3