Alerts This Week
Warning Icon 1 717
Alerts This Week
Warning Icon 1 717

Ubuntu 25.10 Cargo-C Significant Permission Escalation Flaw USN-8139-1

ubuntu
Calendar Grey April 1, 2026
Dist Ubuntu Esm H88
Cargo-c vulnerability on Ubuntu allows permission modifications on directories, posing a risk to system integrity. Update recommended.
cargo-c could be made to modify permissions on arbitrary directories.

Summary

cargo-c could be made to modify permissions on arbitrary directories.

Software Description:

- rust-cargo-c: Helper program to build and install c-like libraries

Details:

It was discovered that tar-rs embedded in cargo-c incorrectly handled

symlinks when unpacking a tar archive. If a user or automated system were

tricked into processing a specially crafted tar archive, a remote attacker

could use this issue to modify permissions of arbitrary directories outside

the extraction root, and possibly escalate privileges.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  cargo-c                         0.10.11-1ubuntu1.1
  librust-cargo-c-dev             0.10.11-1ubuntu1.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8139-1

CVE-2026-33056

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8139-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here