Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-RU-2026:1001-1

Опубликовано: 25 мар. 2026
Источник: suse-cvrf

Описание

Recommended update for rust1.94

This update for rust1.94 fixes the following issues:

This update adds rust1.94.

Release notes can be found externally: https://github.com/rust-lang/rust/releases/tag/1.94.0

  • CVE-2026-31812: avoid unwrapping varint decoding during parameters parsing (bsc#1259623)

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
cargo-1.94.0-150400.24.71.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150400.24.71.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
cargo-1.94.0-150400.24.71.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150400.24.71.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
cargo-1.94.0-150500.27.65.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150500.27.65.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
cargo-1.94.0-150500.27.65.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150500.27.65.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
cargo-1.94.0-150500.27.65.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150500.27.65.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
SUSE Linux Enterprise Server 15 SP4-LTSS
cargo-1.94.0-150400.24.71.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150400.24.71.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
SUSE Linux Enterprise Server 15 SP5-LTSS
cargo-1.94.0-150500.27.65.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150500.27.65.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
SUSE Linux Enterprise Server 15 SP6-LTSS
cargo-1.94.0-150500.27.65.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150500.27.65.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
cargo-1.94.0-150400.24.71.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150400.24.71.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
cargo-1.94.0-150500.27.65.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150500.27.65.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
cargo-1.94.0-150500.27.65.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150500.27.65.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1
openSUSE Leap 15.6
cargo-1.94.0-150500.27.65.1
cargo1.94-1.94.0-150300.7.6.1
rust-1.94.0-150500.27.65.1
rust1.94-1.94.0-150300.7.6.1
rust1.94-src-1.94.0-150300.7.6.1

Описание

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:cargo-1.94.0-150400.24.71.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:cargo1.94-1.94.0-150300.7.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:rust-1.94.0-150400.24.71.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:rust1.94-1.94.0-150300.7.6.1

Ссылки
Уязвимость SUSE-RU-2026:1001-1