Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:67286

Опубликовано: 15 сент. 2026
Источник: rocky
Оценка: Important

Описание

Important: rust security update

Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety. This package includes the Rust compiler and documentation generator.

Security Fix(es):

  • libgit2: libgit2: Denial of Service due to heap out-of-bounds read from malicious Git server (CVE-2026-53587)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
clippyaarch642.el10_2clippy-1.92.0-2.el10_2.aarch64.rpm
rust-toolset-srpm-macrosnoarch2.el10_2rust-toolset-srpm-macros-1.92.0-2.el10_2.noarch.rpm
rust-debugger-commonnoarch2.el10_2rust-debugger-common-1.92.0-2.el10_2.noarch.rpm
rust-toolsetnoarch2.el10_2rust-toolset-1.92.0-2.el10_2.noarch.rpm
rust-gdbnoarch2.el10_2rust-gdb-1.92.0-2.el10_2.noarch.rpm
rust-std-static-wasm32-unknown-unknownnoarch2.el10_2rust-std-static-wasm32-unknown-unknown-1.92.0-2.el10_2.noarch.rpm
rustaarch642.el10_2rust-1.92.0-2.el10_2.aarch64.rpm
cargoaarch642.el10_2cargo-1.92.0-2.el10_2.aarch64.rpm
rust-srcnoarch2.el10_2rust-src-1.92.0-2.el10_2.noarch.rpm
rust-std-staticaarch642.el10_2rust-std-static-1.92.0-2.el10_2.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
redhat
около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
nvd
около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
debian
около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provide ...

rocky
6 дней назад

Important: rust security update