Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 38 FEDORA-2024-bbb141c1ed Critical: Rust Command Injection Fix

fedora
Calendar Grey April 19, 2024
Dist Fedora Esm H88
Fedora has issued a vital security patch for the Rust programming language, addressing the CVE-2024-24576 vulnerability affecting Windows systems. Users are advised to upgrade their Rust environments immediately to prevent potential threats. This fix strengthens the safety of system commands in Rust applications, improving the overall security framework. For detailed instructions on the update, refer to the official Fedora repositories or security bulletins
Security fix for CVE-2024-24576 (Windows command injection)

Summary

Rust is a systems programming language that runs blazingly fast, prevents

segfaults, and guarantees thread safety.

This package includes the Rust compiler and documentation generator.

Update Information:

Security fix for CVE-2024-24576 (Windows command injection)

Change Log

* Tue Apr 9 2024 Josh Stone - 1.77.2-1 - Update to 1.77.2; Fixes RHBZ#2274248 CVE-2024-24576 * Fri Apr 5 2024 Josh Stone - 1.77.0-3 - Ensure more consistency in PGO flags -- fixes Cargo tests

References


[ 1 ] Bug #2265585 - CVE-2024-24576 rust: Fail to Escape Arguments Properly in Microsoft Windows https://bugzilla.redhat.com/show_bug.cgi?id=2265585

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-bbb141c1ed' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rust
Product: Fedora 38
Version: 1.77.2
Release: 1.fc38
Summary: The Rust Programming Language

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here