Tagged “rust”
CVEs tagged rust, newest first.
383 CVEsRSS
GHSA-fqf6-gxhh-2xhwHighuutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
CVE-2026-35341High· 7.1mkfifo: permissions of an existing file are changed after FIFO creation fails
mkfifo: permissions of an existing file are changed after FIFO creation fails
CVE-2026-35361Low· 3.4mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
CVE-2026-35381Low· 3.3cut: -s ignored in -z -d '' newline-delimiter mode
cut: -s ignored in -z -d '' newline-delimiter mode
CVE-2026-54496Critical· 9.3Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
CVE-2026-35342Low· 3.3mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
CVE-2026-35346Low· 3.3comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
CVE-2026-35373Low· 3.3ln: rejects non-UTF-8 source filenames in target-directory mode
ln: rejects non-UTF-8 source filenames in target-directory mode
CVE-2026-35355Medium· 6.3install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
CVE-2026-35343Low· 3.3cut: -s (only-delimited) ignored when delimiter is a newline
cut: -s (only-delimited) ignored when delimiter is a newline
CVE-2026-35356Medium· 6.3install -D: symlink race in directory creation allows arbitrary file overwrite
install -D: symlink race in directory creation allows arbitrary file overwrite
CVE-2026-35369Medium· 5.5kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
CVE-2026-35371Low· 3.3id: pretty-print uses effective GID instead of effective UID for name lookup
id: pretty-print uses effective GID instead of effective UID for name lookup
CVE-2026-35349Medium· 6.7rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode)
rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode)
CVE-2026-35353Low· 3.3mkdir: -m exposes directory with umask perms before chmod (race window)
mkdir: -m exposes directory with umask perms before chmod (race window)
CVE-2026-35370Medium· 4.4id: groups= computed from real GID instead of effective GID
id: groups= computed from real GID instead of effective GID
CVE-2026-35347Medium· 4.4comm: FIFO/pipe inputs are drained before comparison (data loss / hang)
comm: FIFO/pipe inputs are drained before comparison (data loss / hang)
CVE-2026-35363Medium· 5.6rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
CVE-2026-35358Medium· 4.4cp: -R reads device nodes as streams, destroying device semantics
cp: -R reads device nodes as streams, destroying device semantics
CVE-2026-35365Medium· 6.6mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
CVE-2026-35362Low· 3.6uucore: safe_traversal TOCTOU protection only enabled on Linux
uucore: safe_traversal TOCTOU protection only enabled on Linux
CVE-2026-35366Medium· 4.4printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
CVE-2026-35339Medium· 5.5chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
CVE-2026-35338High· 7.3chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
GHSA-2v8p-fqpx-2q3wMedium· 6.2jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)
jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)
GHSA-66m8-c62j-h6v5Medium· 6.2jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow
jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow
GHSA-h72h-ppcx-998pLow· 3.7Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length
Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length
GHSA-443g-gwgp-49x4Low· 3.7zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length
zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length
GHSA-c8w6-x74f-vmg3Medium· 6.5zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
CVE-2026-50185MediumCmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set
Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set