Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 34: 2022-2c73789458 Critical: Rust Race Condition Security Fix

fedora
Calendar Grey January 24, 2022
Dist Fedora Esm H88
Essential security patch addressing race condition vulnerability in Fedora's Rust package. Recompile impacted applications to bolster defenses against potential risks.
Security fix for CVE-2022-21658, a TOCTOU race condition in std::fs::remove_dir_all

Summary

Rust is a systems programming language that runs blazingly fast, prevents

segfaults, and guarantees thread safety.

This package includes the Rust compiler and documentation generator.

Security fix for CVE-2022-21658, a TOCTOU race condition in

std::fs::remove_dir_all. Privileged programs should be rebuilt if they use this

function on paths that may be manipulated with lesser privileges. For more

details, see the upstream [security advisory](https://blog.rust-lang.org/2022/01/20/cve-2022-21658.html).

* Thu Jan 20 2022 Josh Stone - 1.58.1-1

- Update to 1.58.1.

[ 1 ] Bug #2041504 - CVE-2022-21658 rust: Race condition in remove_dir_all leading to removal of files outside of the directory being removed

https://bugzilla.redhat.com/show_bug.cgi?id=2041504

su -c 'dnf upgrade --advisory FEDORA-2022-2c73789458' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 34
Version: 1.58.1
Release: 1.fc34
Summary: The Rust Programming Language

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here