This update for cargo-packaging and rust-bindgen fixes the following issues:
cargo-packaging was updated to version 1.3.0+0:
* CVE-2025-58160: Fixed tracing log pollution in tracing-subscriber
(bsc#1249012)
Other fixes:
* Prevent stripping debug info (bsc#1222175)
rust-bindgen was updated to 0.72.0.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch SUSE-2025-4091=1 openSUSE-SLE-15.6-2025-4091=1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* cargo-packaging-1.3.0+0-150600.3.3.1
* rust-bindgen-debuginfo-0.72.0-150600.13.3.1
* rust-bindgen-debugsource-0.72.0-150600.13.3.1
* rust-bindgen-0.72.0-150600.13.3.1
* bsc#1222175
* bsc#1249012
## References:
* https://www.suse.com/security/cve/CVE-2025-58160.html
* https://bugzilla.suse.com/show_bug.cgi?id=1222175
* https://bugzilla.suse.com/show_bug.cgi?id=1249012
Get the latest Linux and open source security news straight to your inbox.