Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:67285

Опубликовано: 15 сент. 2026
Источник: rocky
Оценка: Important

Описание

Important: rust security update

Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety. This package includes the Rust compiler and documentation generator.

Security Fix(es):

  • libgit2: libgit2: Denial of Service due to heap out-of-bounds read from malicious Git server (CVE-2026-53587)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
cargoaarch642.el9_8cargo-1.92.0-2.el9_8.aarch64.rpm
clippyaarch642.el9_8clippy-1.92.0-2.el9_8.aarch64.rpm
rustaarch642.el9_8rust-1.92.0-2.el9_8.aarch64.rpm
rust-analyzeraarch642.el9_8rust-analyzer-1.92.0-2.el9_8.aarch64.rpm
rust-debugger-commonnoarch2.el9_8rust-debugger-common-1.92.0-2.el9_8.noarch.rpm
rust-docaarch642.el9_8rust-doc-1.92.0-2.el9_8.aarch64.rpm
rustfmtaarch642.el9_8rustfmt-1.92.0-2.el9_8.aarch64.rpm
rust-gdbnoarch2.el9_8rust-gdb-1.92.0-2.el9_8.noarch.rpm
rust-lldbnoarch2.el9_8rust-lldb-1.92.0-2.el9_8.noarch.rpm
rust-srcnoarch2.el9_8rust-src-1.92.0-2.el9_8.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
redhat
около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
nvd
около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
debian
около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provide ...

rocky
6 дней назад

Important: rust security update