Important: rust security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:4634", "synopsis": "Important: rust security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for rust.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Rust Toolset provides the Rust programming language compiler rustc, the cargo build tool and dependency manager, and required libraries. \n\nSecurity Fix(es):\n\n* rust-cargo: cargo does not respect the umask when extracting dependencies (CVE-2023-38497)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2228038", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2228038", "description": ""}], "cves": [{"name": "CVE-2023-38497", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-38497", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-08-24T04:21:28.127982Z", "rpms": {"Rocky Linux 9": {"nvras": ["cargo-0:1.66.1-2.el9_2.aarch64.rpm", "cargo-0:1.66.1-2.el9_2.ppc64le.rpm", "cargo-0:1.66.1-2.el9_2.s390x.rpm", "cargo-0:1.66.1-2.el9_2.x86_64.rpm", "cargo-debuginfo-0:1.66.1-2.el9_2.aarch64.rpm", "cargo-debuginfo-0:1.66.1-2.el9_2.ppc64le.rpm", "cargo-debuginfo-0:1.66.1-2.el9_2.s390x.rpm", "cargo-debuginfo-0:1.66.1-2.el9_2.x86_64.rpm", "clippy-0:1.66.1-2.el9_2.aarch64.rpm", "clippy-0:1.66.1-2.el9_2.ppc64le.rpm", "clippy-0:1.66.1-2.el9_2.s390x.rpm", "clippy-0:1.66.1-2.el9_2.x86_64.rpm", "clippy-debuginfo-0:1.66.1-2.el9_2.aarch64.rpm", "clippy-debuginfo-0:1.66.1-2.el9_2.ppc64le.rpm", "clippy-debuginfo-0:1.66.1-2.el9_2.s390x.rpm","clippy-debuginfo-0:1.66.1-2.el9_2.x86_64.rpm", "rust-0:1.66.1-2.el9_2.aarch64.rpm", "rust-0:1.66.1-2.el9_2.ppc64le.rpm", "rust-0:1.66.1-2.el9_2.s390x.rpm", "rust-0:1.66.1-2.el9_2.src.rpm", "rust-0:1.66.1-2.el9_2.x86_64.rpm", "rust-analysis-0:1.66.1-2.el9_2.aarch64.rpm", "rust-analysis-0:1.66.1-2.el9_2.ppc64le.rpm", "rust-analysis-0:1.66.1-2.el9_2.s390x.rpm", "rust-analysis-0:1.66.1-2.el9_2.x86_64.rpm", "rust-analyzer-0:1.66.1-2.el9_2.aarch64.rpm", "rust-analyzer-0:1.66.1-2.el9_2.ppc64le.rpm", "rust-analyzer-0:1.66.1-2.el9_2.s390x.rpm", "rust-analyzer-0:1.66.1-2.el9_2.x86_64.rpm", "rust-analyzer-debuginfo-0:1.66.1-2.el9_2.aarch64.rpm", "rust-analyzer-debuginfo-0:1.66.1-2.el9_2.ppc64le.rpm", "rust-analyzer-debuginfo-0:1.66.1-2.el9_2.s390x.rpm", "rust-analyzer-debuginfo-0:1.66.1-2.el9_2.x86_64.rpm", "rust-debugger-common-0:1.66.1-2.el9_2.noarch.rpm", "rust-debuginfo-0:1.66.1-2.el9_2.aarch64.rpm", "rust-debuginfo-0:1.66.1-2.el9_2.ppc64le.rpm", "rust-debuginfo-0:1.66.1-2.el9_2.s390x.rpm", "rust-debuginfo-0:1.66.1-2.el9_2.x86_64.rpm", "rust-debugsource-0:1.66.1-2.el9_2.aarch64.rpm", "rust-debugsource-0:1.66.1-2.el9_2.ppc64le.rpm", "rust-debugsource-0:1.66.1-2.el9_2.s390x.rpm", "rust-debugsource-0:1.66.1-2.el9_2.x86_64.rpm", "rust-doc-0:1.66.1-2.el9_2.aarch64.rpm", "rust-doc-0:1.66.1-2.el9_2.ppc64le.rpm", "rust-doc-0:1.66.1-2.el9_2.s390x.rpm", "rust-doc-0:1.66.1-2.el9_2.x86_64.rpm", "rustfmt-0:1.66.1-2.el9_2.aarch64.rpm", "rustfmt-0:1.66.1-2.el9_2.ppc64le.rpm", "rustfmt-0:1.66.1-2.el9_2.s390x.rpm", "rustfmt-0:1.66.1-2.el9_2.x86_64.rpm", "rustfmt-debuginfo-0:1.66.1-2.el9_2.aarch64.rpm", "rustfmt-debuginfo-0:1.66.1-2.el9_2.ppc64le.rpm", "rustfmt-debuginfo-0:1.66.1-2.el9_2.s390x.rpm", "rustfmt-debuginfo-0:1.66.1-2.el9_2.x86_64.rpm", "rust-gdb-0:1.66.1-2.el9_2.noarch.rpm", "rust-lldb-0:1.66.1-2.el9_2.noarch.rpm", "rust-src-0:1.66.1-2.el9_2.noarch.rpm", "rust-std-static-0:1.66.1-2.el9_2.aarch64.rpm", "rust-std-static-0:1.66.1-2.el9_2.i686.rpm", "rust-std-static-0:1.66.1-2.el9_2.ppc64le.rpm","rust-std-static-0:1.66.1-2.el9_2.s390x.rpm", "rust-std-static-0:1.66.1-2.el9_2.x86_64.rpm", "rust-std-static-wasm32-unknown-unknown-0:1.66.1-2.el9_2.noarch.rpm", "rust-std-static-wasm32-wasi-0:1.66.1-2.el9_2.noarch.rpm", "rust-toolset-0:1.66.1-2.el9_2.aarch64.rpm", "rust-toolset-0:1.66.1-2.el9_2.ppc64le.rpm", "rust-toolset-0:1.66.1-2.el9_2.s390x.rpm", "rust-toolset-0:1.66.1-2.el9_2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux 9 has released an update for the Rust Toolchain to tackle various security vulnerabilities. This advisory resolves significant threats and enhances system integrity.. Rust Update, Rocky Linux Advisory, Cargo Security Patch, Rust Toolset Issues. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.