ALSA-2022:1894

Source
https://errata.almalinux.org/8/ALSA-2022-1894.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2022:1894.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2022:1894
Related
Published
2022-05-10T08:06:44Z
Modified
2022-05-10T08:06:43Z
Summary
Moderate: rust-toolset:rhel8 security, bug fix, and enhancement update
Details

Rust Toolset provides the Rust programming language compiler rustc, the cargo build tool and dependency manager, and required libraries.

The following packages have been upgraded to a later upstream version: rust (1.58.0). (BZ#2002883)

Security Fix(es):

  • rust: Race condition in removedirall leading to removal of files outside of the directory being removed (CVE-2022-21658)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

References

Affected packages

AlmaLinux:8 / cargo

Package

Name
cargo

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / cargo-doc

Package

Name
cargo-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / clippy

Package

Name
clippy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rls

Package

Name
rls

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust

Package

Name
rust

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust-analysis

Package

Name
rust-analysis

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust-debugger-common

Package

Name
rust-debugger-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust-doc

Package

Name
rust-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust-gdb

Package

Name
rust-gdb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust-lldb

Package

Name
rust-lldb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust-src

Package

Name
rust-src

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust-std-static

Package

Name
rust-std-static

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust-std-static-wasm32-unknown-unknown

Package

Name
rust-std-static-wasm32-unknown-unknown

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust-std-static-wasm32-wasi

Package

Name
rust-std-static-wasm32-wasi

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rust-toolset

Package

Name
rust-toolset

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3

AlmaLinux:8 / rustfmt

Package

Name
rustfmt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58.1-1.module_el8.6.0+2748+176088b3