Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Warning: Undefined array key "Description" in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 220

Fedora 43: Maturin Critical Tracing Log Pollution CVE-2025-58160 Fix

fedora
Calendar Grey September 12, 2025
Dist Fedora Esm H88
In response to CVE-2025-58160, the latest maturin release for Fedora enhances logging trace capabilities and bolsters overall security.
Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160.

Summary

Build and publish crates with pyo3, rust-cpython and cffi bindings as

well as rust binaries as python packages.

Update Information:

Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160.

Change Log

* Tue Sep 2 2025 Fabio Valentini - 1.8.7-2 - Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160

References


[ 1 ] Bug #2391972 - CVE-2025-58160 maturin: Tracing log pollution [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2391972 [ 2 ] Bug #2391999 - CVE-2025-58160 maturin: Tracing log pollution [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2391999 [ 3 ] Bug #2392038 - CVE-2025-58160 maturin: Tracing log pollution [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2392038

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-39e043b93d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: maturin
Product: Fedora 43
Version: 1.8.7
Release: 2.fc43
Summary: Build and publish Rust crates as Python packages

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here