Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Fedora 44 python-fastar Update CVE-2026-32766 Critical Permissions Issue

fedora
Calendar Grey March 28, 2026
Dist Fedora Esm H88
Fedora 44 update for python-fastar addresses CVEs fixing security risks in Rust-based libraries enhancing functionality.
Update rust-astral-tokio-tar to 0.6.0, fixing CVE-2026-32766

Summary

The fastar library wraps the Rust tar, flate2, and zstd crates, providing a

high-performance way to work with compressed and uncompressed tar archives in

Python.

Update Information:

Update rust-astral-tokio-tar to 0.6.0, fixing CVE-2026-32766. Update rust-tar to 0.4.45, fixing CVE-2026-33056. Update rust-nix to 0.31.2. Update uv and python- uv-build to 0.10.2, rebuilding them with the latest rust-astral-tokio-tar and rust-tar. Update python-fastar to 0.9.0, rebuilding it with the lastest rust- tar. Rebuild maturin with the latest rust-tar.

Change Log

* Sat Mar 21 2026 Benjamin A. Beasley - 0.9.0-2 - Rebuilt with rust-tar 0.4.45 for CVE-2026-33056 * Fri Mar 20 2026 Benjamin A. Beasley - 0.9.0-1 - Update to 0.9.0 (close RHBZ#2449645) * Fri Mar 20 2026 Benjamin A. Beasley - 0.8.0-3 - Allow PyO3 0.28

References


[ 1 ] Bug #2448054 - rust-astral-tokio-tar-0.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2448054 [ 2 ] Bug #2449243 - uv-0.10.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=2449243 [ 3 ] Bug #2449274 - rust-tar-0.4.45 is available https://bugzilla.redhat.com/show_bug.cgi?id=2449274 [ 4 ] Bug #2449338 - python-uv-build-0.10.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=2449338 [ 5 ] Bug #2449645 - python-fastar-0.9.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2449645 [ 6 ] Bug #2449681 - CVE-2026-33056 maturin: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449681 [ 7 ] Bug #2449683 - CVE-2026-33056 python-fastar: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449683 [ 8 ...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e22a7dbf2d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-fastar
Product: Fedora 44
Version: 0.9.0
Release: 2.fc44
Summary: High-level bindings for the Rust tar crate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here