Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20569-1

Опубликовано: 20 апр. 2026
Источник: suse-cvrf

Описание

Security update for rust1.94

This update for rust1.94 fixes the following issues:

Changes in rust1.94:

  • Don't force gcc-15 on SLE-16 and higher (bsc#1261876)

Update to rust1.94.1:

Список пакетов

openSUSE Leap 16.0
cargo1.94-1.94.1-160000.1.1
rust1.94-1.94.1-160000.1.1
rust1.94-src-1.94.1-160000.1.1

Описание

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.


Затронутые продукты
openSUSE Leap 16.0:cargo1.94-1.94.1-160000.1.1
openSUSE Leap 16.0:rust1.94-1.94.1-160000.1.1
openSUSE Leap 16.0:rust1.94-src-1.94.1-160000.1.1

Ссылки