UBUNTU-CVE-2026-5223

Source
https://ubuntu.com/security/CVE-2026-5223
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-5223
Upstream
  • CVE-2026-5223
Published
2026-05-25T10:16:00Z
Modified
2026-06-03T07:15:36.237300740Z
Severity
  • 6.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H CVSS Calculator
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is medium for users of third-party registries. Users of crates.io are not affected, as crates.io forbids uploading crates containing any symlink.

References

Affected packages

Ubuntu:22.04:LTS
rustc

Package

Name
rustc
Purl
pkg:deb/ubuntu/rustc?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.51.0+dfsg1+llvm-1~exp3ubuntu1
1.53.0+dfsg1+llvm-4ubuntu1
1.54.0+dfsg2+llvm-3ubuntu1
1.56.0+dfsg1+llvm-2ubuntu1
1.56.0+dfsg1+llvm-2ubuntu2
1.57.0+dfsg1+llvm-0ubuntu1
1.57.0+dfsg1+llvm-0ubuntu2
1.58.1+dfsg1~ubuntu1-0ubuntu1
1.58.1+dfsg1~ubuntu1-0ubuntu2
1.59.0+dfsg1-1~ubuntu2~22.04.1
1.61.0+dfsg1-1~exp1ubuntu0.22.04.1
1.65.0+dfsg0ubuntu1-0ubuntu0.22.04.1
1.66.1+dfsg0ubuntu1-0ubuntu0.22.04.1
1.70.0+dfsg0ubuntu1~bpo2-0ubuntu0.22.04.1
1.70.0+dfsg0ubuntu1~bpo2-0ubuntu0.22.04.2
1.71.1+dfsg0ubuntu3~bpo0-0ubuntu0.22.04
1.72.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04
1.73.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04
1.74.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04
1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04
1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "cargo"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "libstd-rust-1.75"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-all"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-clippy"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-gdb"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-lldb"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-src"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustc"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustfmt"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.62

Package

Name
rustc-1.62
Purl
pkg:deb/ubuntu/rustc-1.62?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.62.1+dfsg1-1ubuntu0.22.04.1
1.62.1+dfsg1-1ubuntu0.22.04.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.62.1+dfsg1-1ubuntu0.22.04.3",
            "binary_name": "libstd-rust-1.62"
        },
        {
            "binary_version": "1.62.1+dfsg1-1ubuntu0.22.04.3",
            "binary_name": "rust-1.62-all"
        },
        {
            "binary_version": "1.62.1+dfsg1-1ubuntu0.22.04.3",
            "binary_name": "rust-1.62-clippy"
        },
        {
            "binary_version": "1.62.1+dfsg1-1ubuntu0.22.04.3",
            "binary_name": "rust-1.62-gdb"
        },
        {
            "binary_version": "1.62.1+dfsg1-1ubuntu0.22.04.3",
            "binary_name": "rust-1.62-lldb"
        },
        {
            "binary_version": "1.62.1+dfsg1-1ubuntu0.22.04.3",
            "binary_name": "rust-1.62-src"
        },
        {
            "binary_version": "1.62.1+dfsg1-1ubuntu0.22.04.3",
            "binary_name": "rustc-1.62"
        },
        {
            "binary_version": "1.62.1+dfsg1-1ubuntu0.22.04.3",
            "binary_name": "rustfmt-1.62"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.76

Package

Name
rustc-1.76
Purl
pkg:deb/ubuntu/rustc-1.76?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04
1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "cargo-1.76"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "libstd-rust-1.76"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.76-all"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.76-clippy"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.76-gdb"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.76-lldb"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.76-src"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustc-1.76"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustfmt-1.76"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.77

Package

Name
rustc-1.77
Purl
pkg:deb/ubuntu/rustc-1.77?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04
1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "cargo-1.77"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "libstd-rust-1.77"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.77-all"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.77-clippy"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.77-gdb"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.77-lldb"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.77-src"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustc-1.77"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustfmt-1.77"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.78

Package

Name
rustc-1.78
Purl
pkg:deb/ubuntu/rustc-1.78?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04
1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "cargo-1.78"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "libstd-rust-1.78"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.78-all"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.78-clippy"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.78-gdb"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.78-lldb"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.78-src"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustc-1.78"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustfmt-1.78"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.79

Package

Name
rustc-1.79
Purl
pkg:deb/ubuntu/rustc-1.79?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04
1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "cargo-1.79"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "libstd-rust-1.79"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.79-all"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.79-clippy"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.79-gdb"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.79-lldb"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.79-src"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustc-1.79"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustfmt-1.79"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.80

Package

Name
rustc-1.80
Purl
pkg:deb/ubuntu/rustc-1.80?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04
1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "cargo-1.80"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "libstd-rust-1.80"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.80-all"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.80-clippy"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.80-gdb"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.80-lldb"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.80-src"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustc-1.80"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.22.04.1",
            "binary_name": "rustfmt-1.80"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.81

Package

Name
rustc-1.81
Purl
pkg:deb/ubuntu/rustc-1.81?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.81.0+dfsg0ubuntu0-0ubuntu0.22.04
1.81.0+dfsg0ubuntu0-0ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.81.0+dfsg0ubuntu0-0ubuntu0.22.04.1",
            "binary_name": "cargo-1.81"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu0-0ubuntu0.22.04.1",
            "binary_name": "libstd-rust-1.81"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.81-all"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.81-clippy"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.81-gdb"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.81-lldb"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu0-0ubuntu0.22.04.1",
            "binary_name": "rust-1.81-src"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu0-0ubuntu0.22.04.1",
            "binary_name": "rustc-1.81"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu0-0ubuntu0.22.04.1",
            "binary_name": "rustfmt-1.81"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.82

Package

Name
rustc-1.82
Purl
pkg:deb/ubuntu/rustc-1.82?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04
1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04.1",
            "binary_name": "cargo-1.82"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04.1",
            "binary_name": "libstd-rust-1.82"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04.1",
            "binary_name": "rust-1.82-all"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04.1",
            "binary_name": "rust-1.82-clippy"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04.1",
            "binary_name": "rust-1.82-gdb"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04.1",
            "binary_name": "rust-1.82-lldb"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04.1",
            "binary_name": "rust-1.82-src"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04.1",
            "binary_name": "rustc-1.82"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0~jammy-0ubuntu0.22.04.1",
            "binary_name": "rustfmt-1.82"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.83

Package

Name
rustc-1.83
Purl
pkg:deb/ubuntu/rustc-1.83?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04~ppa3
1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04.1",
            "binary_name": "cargo-1.83"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04.1",
            "binary_name": "libstd-rust-1.83"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04.1",
            "binary_name": "rust-1.83-all"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04.1",
            "binary_name": "rust-1.83-clippy"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04.1",
            "binary_name": "rust-1.83-gdb"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04.1",
            "binary_name": "rust-1.83-lldb"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04.1",
            "binary_name": "rust-1.83-src"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04.1",
            "binary_name": "rustc-1.83"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu2~bpo2-0ubuntu2.22.04.1",
            "binary_name": "rustfmt-1.83"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.84

Package

Name
rustc-1.84
Purl
pkg:deb/ubuntu/rustc-1.84?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04
1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04.1",
            "binary_name": "cargo-1.84"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04.1",
            "binary_name": "libstd-rust-1.84"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04.1",
            "binary_name": "rust-1.84-all"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04.1",
            "binary_name": "rust-1.84-clippy"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04.1",
            "binary_name": "rust-1.84-gdb"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04.1",
            "binary_name": "rust-1.84-lldb"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04.1",
            "binary_name": "rust-1.84-src"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04.1",
            "binary_name": "rustc-1.84"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo10-0ubuntu4.22.04.1",
            "binary_name": "rustfmt-1.84"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.85

Package

Name
rustc-1.85
Purl
pkg:deb/ubuntu/rustc-1.85?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.22.03
1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04
1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04.1",
            "binary_name": "cargo-1.85"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04.1",
            "binary_name": "libstd-rust-1.85"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04.1",
            "binary_name": "rust-1.85-all"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04.1",
            "binary_name": "rust-1.85-clippy"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04.1",
            "binary_name": "rust-1.85-gdb"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04.1",
            "binary_name": "rust-1.85-lldb"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04.1",
            "binary_name": "rust-1.85-src"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04.1",
            "binary_name": "rustc-1.85"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu1.22.04.1",
            "binary_name": "rustfmt-1.85"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.89

Package

Name
rustc-1.89
Purl
pkg:deb/ubuntu/rustc-1.89?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.89.0+dfsg~24.04-0ubuntu0.22.04.1
1.89.0+dfsg~24.04-0ubuntu0.22.04.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.22.04.2",
            "binary_name": "cargo-1.89"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.22.04.2",
            "binary_name": "libstd-rust-1.89"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.22.04.2",
            "binary_name": "rust-1.89-all"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.22.04.2",
            "binary_name": "rust-1.89-clippy"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.22.04.2",
            "binary_name": "rust-1.89-gdb"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.22.04.2",
            "binary_name": "rust-1.89-lldb"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.22.04.2",
            "binary_name": "rust-1.89-src"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.22.04.2",
            "binary_name": "rustc-1.89"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.22.04.2",
            "binary_name": "rustfmt-1.89"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.91

Package

Name
rustc-1.91
Purl
pkg:deb/ubuntu/rustc-1.91?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.91.1+dfsg~22.04-0ubuntu0.22.04.2
1.91.1+dfsg~22.04-0ubuntu0.22.04.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.91.1+dfsg~22.04-0ubuntu0.22.04.3",
            "binary_name": "cargo-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg~22.04-0ubuntu0.22.04.3",
            "binary_name": "libstd-rust-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg~22.04-0ubuntu0.22.04.3",
            "binary_name": "rust-1.91-all"
        },
        {
            "binary_version": "1.91.1+dfsg~22.04-0ubuntu0.22.04.3",
            "binary_name": "rust-1.91-clippy"
        },
        {
            "binary_version": "1.91.1+dfsg~22.04-0ubuntu0.22.04.3",
            "binary_name": "rust-1.91-gdb"
        },
        {
            "binary_version": "1.91.1+dfsg~22.04-0ubuntu0.22.04.3",
            "binary_name": "rust-1.91-lldb"
        },
        {
            "binary_version": "1.91.1+dfsg~22.04-0ubuntu0.22.04.3",
            "binary_name": "rust-1.91-src"
        },
        {
            "binary_version": "1.91.1+dfsg~22.04-0ubuntu0.22.04.3",
            "binary_name": "rustc-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg~22.04-0ubuntu0.22.04.3",
            "binary_name": "rustfmt-1.91"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
Ubuntu:24.04:LTS
rustc

Package

Name
rustc
Purl
pkg:deb/ubuntu/rustc?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.71.1+dfsg0ubuntu2-0ubuntu1
1.73.0+dfsg0ubuntu1-0ubuntu1
1.74.1+dfsg0ubuntu1-0ubuntu1
1.75.0+dfsg0ubuntu1-0ubuntu1
1.75.0+dfsg0ubuntu1-0ubuntu6
1.75.0+dfsg0ubuntu1-0ubuntu7
1.75.0+dfsg0ubuntu1-0ubuntu7.1
1.75.0+dfsg0ubuntu1-0ubuntu7.4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.75.0+dfsg0ubuntu1-0ubuntu7.4",
            "binary_name": "cargo"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1-0ubuntu7.4",
            "binary_name": "libstd-rust-1.75"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1-0ubuntu7.4",
            "binary_name": "rust-all"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1-0ubuntu7.4",
            "binary_name": "rust-clippy"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1-0ubuntu7.4",
            "binary_name": "rust-gdb"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1-0ubuntu7.4",
            "binary_name": "rust-lldb"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1-0ubuntu7.4",
            "binary_name": "rust-src"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1-0ubuntu7.4",
            "binary_name": "rustc"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1-0ubuntu7.4",
            "binary_name": "rustfmt"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.74

Package

Name
rustc-1.74
Purl
pkg:deb/ubuntu/rustc-1.74?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.74.1+dfsg0ubuntu1-0ubuntu2
1.74.1+dfsg0ubuntu1-0ubuntu13
1.74.1+dfsg0ubuntu1-0ubuntu15

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.74.1+dfsg0ubuntu1-0ubuntu15",
            "binary_name": "cargo-1.74"
        },
        {
            "binary_version": "1.74.1+dfsg0ubuntu1-0ubuntu15",
            "binary_name": "rust-1.74-all"
        },
        {
            "binary_version": "1.74.1+dfsg0ubuntu1-0ubuntu15",
            "binary_name": "rust-1.74-clippy"
        },
        {
            "binary_version": "1.74.1+dfsg0ubuntu1-0ubuntu15",
            "binary_name": "rust-1.74-gdb"
        },
        {
            "binary_version": "1.74.1+dfsg0ubuntu1-0ubuntu15",
            "binary_name": "rust-1.74-lldb"
        },
        {
            "binary_version": "1.74.1+dfsg0ubuntu1-0ubuntu15",
            "binary_name": "rust-1.74-src"
        },
        {
            "binary_version": "1.74.1+dfsg0ubuntu1-0ubuntu15",
            "binary_name": "rustc-1.74"
        },
        {
            "binary_version": "1.74.1+dfsg0ubuntu1-0ubuntu15",
            "binary_name": "rustfmt-1.74"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.76

Package

Name
rustc-1.76
Purl
pkg:deb/ubuntu/rustc-1.76?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.76.0+dfsg0ubuntu1-0ubuntu0.24.04
1.76.0+dfsg0ubuntu1-0ubuntu0.24.04.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.76.0+dfsg0ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "cargo-1.76"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "libstd-rust-1.76"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rust-1.76-all"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rust-1.76-clippy"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rust-1.76-gdb"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rust-1.76-lldb"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rust-1.76-src"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rustc-1.76"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rustfmt-1.76"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.77

Package

Name
rustc-1.77
Purl
pkg:deb/ubuntu/rustc-1.77?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.77.2+dfsg1ubuntu1-0ubuntu0.24.04
1.77.2+dfsg1ubuntu1-0ubuntu0.24.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.77.2+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "cargo-1.77"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "libstd-rust-1.77"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.77-all"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.77-clippy"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.77-gdb"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.77-lldb"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.77-src"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rustc-1.77"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rustfmt-1.77"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.78

Package

Name
rustc-1.78
Purl
pkg:deb/ubuntu/rustc-1.78?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.78.0+dfsg1ubuntu1-0ubuntu0.24.04
1.78.0+dfsg1ubuntu1-0ubuntu0.24.04.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.78.0+dfsg1ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "cargo-1.78"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "libstd-rust-1.78"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rust-1.78-all"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rust-1.78-clippy"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rust-1.78-gdb"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rust-1.78-lldb"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rust-1.78-src"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rustc-1.78"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1-0ubuntu0.24.04.2",
            "binary_name": "rustfmt-1.78"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.79

Package

Name
rustc-1.79
Purl
pkg:deb/ubuntu/rustc-1.79?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.79.0+dfsg1ubuntu1-0ubuntu0.24.04
1.79.0+dfsg1ubuntu1-0ubuntu0.24.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.79.0+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "cargo-1.79"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "libstd-rust-1.79"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.79-all"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.79-clippy"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.79-gdb"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.79-lldb"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.79-src"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rustc-1.79"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rustfmt-1.79"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.80

Package

Name
rustc-1.80
Purl
pkg:deb/ubuntu/rustc-1.80?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.80.1+dfsg0ubuntu1-0ubuntu0.24.04
1.80.1+dfsg0ubuntu1-0ubuntu0.24.04.01

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.80.1+dfsg0ubuntu1-0ubuntu0.24.04.01",
            "binary_name": "cargo-1.80"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1-0ubuntu0.24.04.01",
            "binary_name": "libstd-rust-1.80"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1-0ubuntu0.24.04.01",
            "binary_name": "rust-1.80-all"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1-0ubuntu0.24.04.01",
            "binary_name": "rust-1.80-clippy"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1-0ubuntu0.24.04.01",
            "binary_name": "rust-1.80-gdb"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1-0ubuntu0.24.04.01",
            "binary_name": "rust-1.80-lldb"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1-0ubuntu0.24.04.01",
            "binary_name": "rust-1.80-src"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1-0ubuntu0.24.04.01",
            "binary_name": "rustc-1.80"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1-0ubuntu0.24.04.01",
            "binary_name": "rustfmt-1.80"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.81

Package

Name
rustc-1.81
Purl
pkg:deb/ubuntu/rustc-1.81?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.81.0+dfsg0ubuntu1-0ubuntu0.24.04
1.81.0+dfsg0ubuntu1-0ubuntu0.24.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.81.0+dfsg0ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "cargo-1.81"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "libstd-rust-1.81"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.81-all"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.81-clippy"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.81-gdb"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.81-lldb"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rust-1.81-src"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rustc-1.81"
        },
        {
            "binary_version": "1.81.0+dfsg0ubuntu1-0ubuntu0.24.04.1",
            "binary_name": "rustfmt-1.81"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.82

Package

Name
rustc-1.82
Purl
pkg:deb/ubuntu/rustc-1.82?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.82.0+dfsg0ubuntu0-0ubuntu0.24.04
1.82.0+dfsg0ubuntu0-0ubuntu0.24.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.82.0+dfsg0ubuntu0-0ubuntu0.24.04.1",
            "binary_name": "cargo-1.82"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0-0ubuntu0.24.04.1",
            "binary_name": "libstd-rust-1.82"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0-0ubuntu0.24.04.1",
            "binary_name": "rust-1.82-all"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0-0ubuntu0.24.04.1",
            "binary_name": "rust-1.82-clippy"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0-0ubuntu0.24.04.1",
            "binary_name": "rust-1.82-gdb"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0-0ubuntu0.24.04.1",
            "binary_name": "rust-1.82-lldb"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0-0ubuntu0.24.04.1",
            "binary_name": "rust-1.82-src"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0-0ubuntu0.24.04.1",
            "binary_name": "rustc-1.82"
        },
        {
            "binary_version": "1.82.0+dfsg0ubuntu0-0ubuntu0.24.04.1",
            "binary_name": "rustfmt-1.82"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.83

Package

Name
rustc-1.83
Purl
pkg:deb/ubuntu/rustc-1.83?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04
1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04.1",
            "binary_name": "cargo-1.83"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04.1",
            "binary_name": "libstd-rust-1.83"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04.1",
            "binary_name": "rust-1.83-all"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04.1",
            "binary_name": "rust-1.83-clippy"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04.1",
            "binary_name": "rust-1.83-gdb"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04.1",
            "binary_name": "rust-1.83-lldb"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04.1",
            "binary_name": "rust-1.83-src"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04.1",
            "binary_name": "rustc-1.83"
        },
        {
            "binary_version": "1.83.0+dfsg0ubuntu1~bpo2-0ubuntu0.24.04.1",
            "binary_name": "rustfmt-1.83"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.84

Package

Name
rustc-1.84
Purl
pkg:deb/ubuntu/rustc-1.84?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04
1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04.1",
            "binary_name": "cargo-1.84"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04.1",
            "binary_name": "libstd-rust-1.84"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04.1",
            "binary_name": "rust-1.84-all"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04.1",
            "binary_name": "rust-1.84-clippy"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04.1",
            "binary_name": "rust-1.84-gdb"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04.1",
            "binary_name": "rust-1.84-lldb"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04.1",
            "binary_name": "rust-1.84-src"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04.1",
            "binary_name": "rustc-1.84"
        },
        {
            "binary_version": "1.84.1+dfsg0ubuntu1~bpo2-0ubuntu2.24.04.1",
            "binary_name": "rustfmt-1.84"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.85

Package

Name
rustc-1.85
Purl
pkg:deb/ubuntu/rustc-1.85?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04
1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04.2",
            "binary_name": "cargo-1.85"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04.2",
            "binary_name": "libstd-rust-1.85"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04.2",
            "binary_name": "rust-1.85-all"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04.2",
            "binary_name": "rust-1.85-clippy"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04.2",
            "binary_name": "rust-1.85-gdb"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04.2",
            "binary_name": "rust-1.85-lldb"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04.2",
            "binary_name": "rust-1.85-src"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04.2",
            "binary_name": "rustc-1.85"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2~bpo0-0ubuntu0.24.04.2",
            "binary_name": "rustfmt-1.85"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.89

Package

Name
rustc-1.89
Purl
pkg:deb/ubuntu/rustc-1.89?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.89.0+dfsg~24.04-0ubuntu0.24.04.1
1.89.0+dfsg~24.04-0ubuntu0.24.04.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.24.04.2",
            "binary_name": "cargo-1.89"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.24.04.2",
            "binary_name": "libstd-rust-1.89"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.24.04.2",
            "binary_name": "rust-1.89-all"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.24.04.2",
            "binary_name": "rust-1.89-clippy"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.24.04.2",
            "binary_name": "rust-1.89-gdb"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.24.04.2",
            "binary_name": "rust-1.89-lldb"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.24.04.2",
            "binary_name": "rust-1.89-src"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.24.04.2",
            "binary_name": "rustc-1.89"
        },
        {
            "binary_version": "1.89.0+dfsg~24.04-0ubuntu0.24.04.2",
            "binary_name": "rustfmt-1.89"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.91

Package

Name
rustc-1.91
Purl
pkg:deb/ubuntu/rustc-1.91?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.91.1+dfsg~24.04-0ubuntu0.24.04.1
1.91.1+dfsg~24.04-0ubuntu0.24.04.2
1.91.1+dfsg~24.04-0ubuntu0.24.04.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.91.1+dfsg~24.04-0ubuntu0.24.04.3",
            "binary_name": "cargo-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg~24.04-0ubuntu0.24.04.3",
            "binary_name": "libstd-rust-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg~24.04-0ubuntu0.24.04.3",
            "binary_name": "rust-1.91-all"
        },
        {
            "binary_version": "1.91.1+dfsg~24.04-0ubuntu0.24.04.3",
            "binary_name": "rust-1.91-clippy"
        },
        {
            "binary_version": "1.91.1+dfsg~24.04-0ubuntu0.24.04.3",
            "binary_name": "rust-1.91-gdb"
        },
        {
            "binary_version": "1.91.1+dfsg~24.04-0ubuntu0.24.04.3",
            "binary_name": "rust-1.91-lldb"
        },
        {
            "binary_version": "1.91.1+dfsg~24.04-0ubuntu0.24.04.3",
            "binary_name": "rust-1.91-src"
        },
        {
            "binary_version": "1.91.1+dfsg~24.04-0ubuntu0.24.04.3",
            "binary_name": "rustc-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg~24.04-0ubuntu0.24.04.3",
            "binary_name": "rustfmt-1.91"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
Ubuntu:25.10
rustc-1.85

Package

Name
rustc-1.85
Purl
pkg:deb/ubuntu/rustc-1.85?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.85.1+dfsg0ubuntu1-0ubuntu1
1.85.1+dfsg0ubuntu2-0ubuntu1
1.85.1+dfsg0ubuntu2-0ubuntu1.25.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.85.1+dfsg0ubuntu2-0ubuntu1.25.04.1",
            "binary_name": "cargo-1.85"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2-0ubuntu1.25.04.1",
            "binary_name": "libstd-rust-1.85"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2-0ubuntu1.25.04.1",
            "binary_name": "rust-1.85-all"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2-0ubuntu1.25.04.1",
            "binary_name": "rust-1.85-clippy"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2-0ubuntu1.25.04.1",
            "binary_name": "rust-1.85-gdb"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2-0ubuntu1.25.04.1",
            "binary_name": "rust-1.85-lldb"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2-0ubuntu1.25.04.1",
            "binary_name": "rust-1.85-src"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2-0ubuntu1.25.04.1",
            "binary_name": "rustc-1.85"
        },
        {
            "binary_version": "1.85.1+dfsg0ubuntu2-0ubuntu1.25.04.1",
            "binary_name": "rustfmt-1.85"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.88

Package

Name
rustc-1.88
Purl
pkg:deb/ubuntu/rustc-1.88?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.88.0+dfsg0ubuntu1-0ubuntu1
1.88.0+dfsg0ubuntu1-0ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.88.0+dfsg0ubuntu1-0ubuntu2",
            "binary_name": "cargo-1.88"
        },
        {
            "binary_version": "1.88.0+dfsg0ubuntu1-0ubuntu2",
            "binary_name": "libstd-rust-1.88"
        },
        {
            "binary_version": "1.88.0+dfsg0ubuntu1-0ubuntu2",
            "binary_name": "rust-1.88-all"
        },
        {
            "binary_version": "1.88.0+dfsg0ubuntu1-0ubuntu2",
            "binary_name": "rust-1.88-clippy"
        },
        {
            "binary_version": "1.88.0+dfsg0ubuntu1-0ubuntu2",
            "binary_name": "rust-1.88-gdb"
        },
        {
            "binary_version": "1.88.0+dfsg0ubuntu1-0ubuntu2",
            "binary_name": "rust-1.88-lldb"
        },
        {
            "binary_version": "1.88.0+dfsg0ubuntu1-0ubuntu2",
            "binary_name": "rust-1.88-src"
        },
        {
            "binary_version": "1.88.0+dfsg0ubuntu1-0ubuntu2",
            "binary_name": "rustc-1.88"
        },
        {
            "binary_version": "1.88.0+dfsg0ubuntu1-0ubuntu2",
            "binary_name": "rustfmt-1.88"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.91

Package

Name
rustc-1.91
Purl
pkg:deb/ubuntu/rustc-1.91?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.91.1+dfsg-0ubuntu3~25.10.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3~25.10.1",
            "binary_name": "cargo-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3~25.10.1",
            "binary_name": "libstd-rust-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3~25.10.1",
            "binary_name": "rust-1.91-all"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3~25.10.1",
            "binary_name": "rust-1.91-clippy"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3~25.10.1",
            "binary_name": "rust-1.91-gdb"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3~25.10.1",
            "binary_name": "rust-1.91-lldb"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3~25.10.1",
            "binary_name": "rust-1.91-src"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3~25.10.1",
            "binary_name": "rustc-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3~25.10.1",
            "binary_name": "rustfmt-1.91"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
Ubuntu:26.04:LTS
rustc-1.91

Package

Name
rustc-1.91
Purl
pkg:deb/ubuntu/rustc-1.91?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.91.1+dfsg-0ubuntu1
1.91.1+dfsg-0ubuntu2
1.91.1+dfsg-0ubuntu3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3",
            "binary_name": "cargo-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3",
            "binary_name": "libstd-rust-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3",
            "binary_name": "rust-1.91-all"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3",
            "binary_name": "rust-1.91-clippy"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3",
            "binary_name": "rust-1.91-gdb"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3",
            "binary_name": "rust-1.91-lldb"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3",
            "binary_name": "rust-1.91-src"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3",
            "binary_name": "rustc-1.91"
        },
        {
            "binary_version": "1.91.1+dfsg-0ubuntu3",
            "binary_name": "rustfmt-1.91"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.92

Package

Name
rustc-1.92
Purl
pkg:deb/ubuntu/rustc-1.92?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.92.0+dfsg-0ubuntu1
1.92.0+dfsg-0ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.92.0+dfsg-0ubuntu2",
            "binary_name": "cargo-1.92"
        },
        {
            "binary_version": "1.92.0+dfsg-0ubuntu2",
            "binary_name": "libstd-rust-1.92"
        },
        {
            "binary_version": "1.92.0+dfsg-0ubuntu2",
            "binary_name": "rust-1.92-all"
        },
        {
            "binary_version": "1.92.0+dfsg-0ubuntu2",
            "binary_name": "rust-1.92-clippy"
        },
        {
            "binary_version": "1.92.0+dfsg-0ubuntu2",
            "binary_name": "rust-1.92-gdb"
        },
        {
            "binary_version": "1.92.0+dfsg-0ubuntu2",
            "binary_name": "rust-1.92-lldb"
        },
        {
            "binary_version": "1.92.0+dfsg-0ubuntu2",
            "binary_name": "rust-1.92-src"
        },
        {
            "binary_version": "1.92.0+dfsg-0ubuntu2",
            "binary_name": "rustc-1.92"
        },
        {
            "binary_version": "1.92.0+dfsg-0ubuntu2",
            "binary_name": "rustfmt-1.92"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.93

Package

Name
rustc-1.93
Purl
pkg:deb/ubuntu/rustc-1.93?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.93.1+dfsg-0ubuntu4
1.93.1+dfsg-0ubuntu5
1.93.1+dfsg-0ubuntu6

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.93.1+dfsg-0ubuntu6",
            "binary_name": "cargo-1.93"
        },
        {
            "binary_version": "1.93.1+dfsg-0ubuntu6",
            "binary_name": "libstd-rust-1.93"
        },
        {
            "binary_version": "1.93.1+dfsg-0ubuntu6",
            "binary_name": "rust-1.93-all"
        },
        {
            "binary_version": "1.93.1+dfsg-0ubuntu6",
            "binary_name": "rust-1.93-clippy"
        },
        {
            "binary_version": "1.93.1+dfsg-0ubuntu6",
            "binary_name": "rust-1.93-gdb"
        },
        {
            "binary_version": "1.93.1+dfsg-0ubuntu6",
            "binary_name": "rust-1.93-lldb"
        },
        {
            "binary_version": "1.93.1+dfsg-0ubuntu6",
            "binary_name": "rust-1.93-miri"
        },
        {
            "binary_version": "1.93.1+dfsg-0ubuntu6",
            "binary_name": "rust-1.93-src"
        },
        {
            "binary_version": "1.93.1+dfsg-0ubuntu6",
            "binary_name": "rustc-1.93"
        },
        {
            "binary_version": "1.93.1+dfsg-0ubuntu6",
            "binary_name": "rustfmt-1.93"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
Ubuntu:Pro:14.04:LTS
rustc

Package

Name
rustc
Purl
pkg:deb/ubuntu/rustc?arch=source&distro=trusty%2Fesm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.15.1+dfsg0-1~exp1ubuntu2~14.04.7
1.17.0+dfsg2-8~ubuntu0.14.04.3
1.21.0+dfsg1+llvm-0ubuntu3~14.04.5
1.22.1+dfsg1+llvm-0ubuntu2~14.04.2
1.24.1+dfsg1+llvm-0ubuntu1~14.04.1
1.25.0+dfsg1+llvm-0ubuntu1~14.04.1
1.28.0+dfsg1+llvm-0ubuntu1~14.04.1
1.30.0+dfsg1+llvm-2ubuntu1~14.04.1
1.31.0+dfsg1+llvm-2ubuntu1~14.04.1
1.31.0+dfsg1+llvm-2ubuntu1~14.04.1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.31.0+dfsg1+llvm-2ubuntu1~14.04.1ubuntu1",
            "binary_name": "libstd-rust-1.31"
        },
        {
            "binary_version": "1.31.0+dfsg1+llvm-2ubuntu1~14.04.1ubuntu1",
            "binary_name": "rust-gdb"
        },
        {
            "binary_version": "1.31.0+dfsg1+llvm-2ubuntu1~14.04.1ubuntu1",
            "binary_name": "rust-lldb"
        },
        {
            "binary_version": "1.31.0+dfsg1+llvm-2ubuntu1~14.04.1ubuntu1",
            "binary_name": "rust-src"
        },
        {
            "binary_version": "1.31.0+dfsg1+llvm-2ubuntu1~14.04.1ubuntu1",
            "binary_name": "rustc"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
Ubuntu:Pro:16.04:LTS
cargo

Package

Name
cargo
Purl
pkg:deb/ubuntu/cargo?arch=source&distro=esm-apps%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.8.0-1
0.16.0-0ubuntu1~16.04.1
0.18.0-0ubuntu0.16.04.1
0.22.0-0ubuntu0.16.04.1
0.23.0-0ubuntu0.16.04.1
0.25.0-1ubuntu1~16.04.1
0.26.0-0ubuntu2~16.04.1
0.29.0-1ubuntu1~16.04.1
0.31.0-3ubuntu1~16.04.1
0.32.0-1~exp1ubuntu1~16.04.1
0.33.0-1ubuntu1~16.04.1
0.35.0-0ubuntu1~16.04.1
0.36.0-0ubuntu1~16.04.1
0.37.0-3ubuntu1~16.04.1
0.38.0-0ubuntu1~16.04.1
0.40.0-3ubuntu1~16.04.1
0.42.0-0ubuntu1~16.04.1
0.44.1-0ubuntu1~16.04.1
0.47.0-1~exp1ubuntu1~16.04.1
0.47.0-1~exp1ubuntu1~16.04.1+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.47.0-1~exp1ubuntu1~16.04.1+esm1",
            "binary_name": "cargo"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc

Package

Name
rustc
Purl
pkg:deb/ubuntu/rustc?arch=source&distro=esm-infra%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7.0+dfsg1-1
1.15.1+dfsg0-1~exp1ubuntu2~16.04.3
1.17.0+dfsg2-8~ubuntu0.16.04.2
1.21.0+dfsg1+llvm-0ubuntu3~16.04.1
1.22.1+dfsg1+llvm-0ubuntu2~16.04.2
1.24.1+dfsg1+llvm-0ubuntu1~16.04.1
1.25.0+dfsg1+llvm-0ubuntu1~16.04.1
1.28.0+dfsg1+llvm-0ubuntu1~16.04.1
1.30.0+dfsg1+llvm-2ubuntu1~16.04.1
1.31.0+dfsg1+llvm-2ubuntu1~16.04.1
1.32.0+dfsg1+llvm-1ubuntu1~16.04.1
1.34.1+dfsg2+llvm-0ubuntu1~16.04.1
1.35.0+dfsg0.1+llvm-0ubuntu1~16.04.1
1.36.0+dfsg1+llvm-2ubuntu1~16.04.1
1.37.0+dfsg1+llvm-1ubuntu1~16.04.1
1.39.0+dfsg1+llvm-3ubuntu1~16.04.1
1.41.0+dfsg1+llvm-0ubuntu1~16.04.1
1.43.0+dfsg1+llvm-1~exp1ubuntu2~16.04.1
1.47.0+dfsg1+llvm-1ubuntu1~16.04.1
1.47.0+dfsg1+llvm-1ubuntu1~16.04.1ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.47.0+dfsg1+llvm-1ubuntu1~16.04.1ubuntu2",
            "binary_name": "libstd-rust-1.47"
        },
        {
            "binary_version": "1.47.0+dfsg1+llvm-1ubuntu1~16.04.1ubuntu2",
            "binary_name": "rust-gdb"
        },
        {
            "binary_version": "1.47.0+dfsg1+llvm-1ubuntu1~16.04.1ubuntu2",
            "binary_name": "rust-lldb"
        },
        {
            "binary_version": "1.47.0+dfsg1+llvm-1ubuntu1~16.04.1ubuntu2",
            "binary_name": "rust-src"
        },
        {
            "binary_version": "1.47.0+dfsg1+llvm-1ubuntu1~16.04.1ubuntu2",
            "binary_name": "rustc"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
Ubuntu:Pro:18.04:LTS
cargo

Package

Name
cargo
Purl
pkg:deb/ubuntu/cargo?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.19.0-0ubuntu1
0.22.0-0ubuntu1
0.22.0-0ubuntu2
0.23.0-0ubuntu1
0.24.0-1ubuntu1
0.25.0-1ubuntu1
0.26.0-0ubuntu1
0.26.0-0ubuntu2
0.29.0-1ubuntu1~18.04.1
0.31.0-3ubuntu1~18.04.4
0.32.0-1~exp1ubuntu1~18.04.1
0.33.0-1ubuntu1~18.04.1
0.35.0-0ubuntu1~18.04.1
0.36.0-0ubuntu1~18.04.1
0.37.0-3ubuntu1~18.04.1
0.38.0-0ubuntu1~18.04.1
0.40.0-3ubuntu1~18.04.1
0.42.0-0ubuntu1~18.04.1
0.44.1-0ubuntu1~18.04.1
0.47.0-1~exp1ubuntu1~18.04.1
0.52.0-0ubuntu1~18.04.1
0.54.0-0ubuntu1~18.04.1
0.58.0-0ubuntu1~18.04.1
0.60.0ubuntu1-0ubuntu1~18.04.1
0.62.0ubuntu0libgit2-0ubuntu0.18.04.1
0.66.0+ds0ubuntu0.libgit2-0ubuntu0.18.04
0.66.0+ds0ubuntu0.libgit2-0ubuntu0.18.04.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.66.0+ds0ubuntu0.libgit2-0ubuntu0.18.04.1~esm1",
            "binary_name": "cargo"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc

Package

Name
rustc
Purl
pkg:deb/ubuntu/rustc?arch=source&distro=esm-infra%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.18.0+dfsg1-4ubuntu1
1.24.1+dfsg1+llvm-0ubuntu1
1.24.1+dfsg1+llvm-0ubuntu2
1.25.0+dfsg1+llvm-0ubuntu1
1.28.0+dfsg1+llvm-0ubuntu1~18.04.1
1.30.0+dfsg1+llvm-2ubuntu1~18.04.1
1.31.0+dfsg1+llvm-2ubuntu1~18.04.1
1.32.0+dfsg1+llvm-1ubuntu1~18.04.1
1.34.1+dfsg2+llvm-0ubuntu1~18.04.1
1.35.0+dfsg0.1+llvm-0ubuntu1~18.04.1
1.36.0+dfsg1+llvm-2ubuntu1~18.04.1
1.37.0+dfsg1+llvm-1ubuntu1~18.04.1
1.39.0+dfsg1+llvm-3ubuntu1~18.04.1
1.41.0+dfsg1+llvm-0ubuntu1~18.04.1
1.43.0+dfsg1+llvm-1~exp1ubuntu2~18.04.1
1.47.0+dfsg1+llvm-1ubuntu1~18.04.1
1.51.0+dfsg1+llvm-1~exp3ubuntu1~18.04.1
1.53.0+dfsg1+llvm-4ubuntu1~18.04.1
1.57.0+dfsg1+llvm-0ubuntu1~18.04.1
1.59.0+dfsg1~ubuntu1~llvm-1~ubuntu1~18.04.2
1.61.0+dfsg1~llvm-1~exp1ubuntu0.18.04.1
1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.18.04
1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.18.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.18.04.1",
            "binary_name": "libstd-rust-1.65"
        },
        {
            "binary_version": "1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.18.04.1",
            "binary_name": "rust-all"
        },
        {
            "binary_version": "1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.18.04.1",
            "binary_name": "rust-clippy"
        },
        {
            "binary_version": "1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.18.04.1",
            "binary_name": "rust-gdb"
        },
        {
            "binary_version": "1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.18.04.1",
            "binary_name": "rust-lldb"
        },
        {
            "binary_version": "1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.18.04.1",
            "binary_name": "rust-src"
        },
        {
            "binary_version": "1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.18.04.1",
            "binary_name": "rustc"
        },
        {
            "binary_version": "1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.18.04.1",
            "binary_name": "rustfmt"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
Ubuntu:Pro:20.04:LTS
cargo

Package

Name
cargo
Purl
pkg:deb/ubuntu/cargo?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.37.0-3ubuntu2
0.38.0-0ubuntu1
0.39.0-0ubuntu1
0.39.0+really0.38.0-0ubuntu1
0.39.0+really0.39.0-0ubuntu1
0.40.0-3ubuntu1
0.40.0-3ubuntu2
0.41.0-0ubuntu1
0.42.0-0ubuntu1
0.44.1-0ubuntu1~20.04.1
0.47.0-1~exp1ubuntu1~20.04.1
0.52.0-0ubuntu1~20.04.1
0.54.0-0ubuntu1~20.04.1
0.58.0-0ubuntu1~20.04.1
0.60.0ubuntu1-0ubuntu1~20.04.1
0.62.0ubuntu0libgit2-0ubuntu0.20.04.1
0.66.0+ds0ubuntu0.libgit2-0ubuntu0.20.04
0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2
0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2+esm1",
            "binary_name": "cargo"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc

Package

Name
rustc
Purl
pkg:deb/ubuntu/rustc?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.37.0+dfsg1+llvm-1ubuntu1
1.38.0+dfsg0.2+llvm-0ubuntu1
1.38.0+dfsg0.2+llvm-0ubuntu2
1.39.0+dfsg1+llvm-3ubuntu1
1.40.0+dfsg1+llvm-5ubuntu1
1.41.0+dfsg1+llvm-0ubuntu1
1.41.0+dfsg1+llvm-0ubuntu2
1.43.0+dfsg1+llvm-1~exp1ubuntu1~20.04.1
1.47.0+dfsg1+llvm-1ubuntu1~20.04.1
1.51.0+dfsg1+llvm-1~exp3ubuntu1~20.04.2
1.53.0+dfsg1+llvm-4ubuntu1~20.04.1
1.57.0+dfsg1+llvm-0ubuntu1~20.04.1
1.59.0+dfsg1~ubuntu1~llvm-1~ubuntu1~20.04.2
1.61.0+dfsg1~llvm-1~exp1ubuntu0.20.04.1
1.65.0+dfsg0ubuntu1~llvm2-0ubuntu0.20.04
1.66.1+dfsg0ubuntu1~llvm-0ubuntu0.20.04
1.70.0+dfsg0ubuntu1~bpo2-0ubuntu0.20.04
1.70.0+dfsg0ubuntu1~bpo2-0ubuntu0.20.04.1
1.71.1+dfsg0ubuntu3~bpo0-0ubuntu0.20.04
1.72.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04
1.73.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1
1.74.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1
1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04
1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "cargo"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "libstd-rust-1.75"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-all"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-clippy"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-gdb"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-lldb"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-src"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rustc"
        },
        {
            "binary_version": "1.75.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rustfmt"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.76

Package

Name
rustc-1.76
Purl
pkg:deb/ubuntu/rustc-1.76?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04
1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "cargo-1.76"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "libstd-rust-1.76"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.76-all"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.76-clippy"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.76-gdb"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.76-lldb"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.76-src"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rustc-1.76"
        },
        {
            "binary_version": "1.76.0+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rustfmt-1.76"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.77

Package

Name
rustc-1.77
Purl
pkg:deb/ubuntu/rustc-1.77?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04
1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "cargo-1.77"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "libstd-rust-1.77"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.77-all"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.77-clippy"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.77-gdb"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.77-lldb"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.77-src"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rustc-1.77"
        },
        {
            "binary_version": "1.77.2+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rustfmt-1.77"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.78

Package

Name
rustc-1.78
Purl
pkg:deb/ubuntu/rustc-1.78?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04
1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "cargo-1.78"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "libstd-rust-1.78"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.78-all"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.78-clippy"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.78-gdb"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.78-lldb"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.78-src"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rustc-1.78"
        },
        {
            "binary_version": "1.78.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rustfmt-1.78"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.79

Package

Name
rustc-1.79
Purl
pkg:deb/ubuntu/rustc-1.79?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.1
1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.3",
            "binary_name": "cargo-1.79"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.3",
            "binary_name": "libstd-rust-1.79"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.3",
            "binary_name": "rust-1.79-all"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.3",
            "binary_name": "rust-1.79-clippy"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.3",
            "binary_name": "rust-1.79-gdb"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.3",
            "binary_name": "rust-1.79-lldb"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.3",
            "binary_name": "rust-1.79-src"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.3",
            "binary_name": "rustc-1.79"
        },
        {
            "binary_version": "1.79.0+dfsg1ubuntu1~bpo0-0ubuntu0.20.04.3",
            "binary_name": "rustfmt-1.79"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
rustc-1.80

Package

Name
rustc-1.80
Purl
pkg:deb/ubuntu/rustc-1.80?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04
1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "cargo-1.80"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "libstd-rust-1.80"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.80-all"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.80-clippy"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.80-gdb"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.80-lldb"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rust-1.80-src"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rustc-1.80"
        },
        {
            "binary_version": "1.80.1+dfsg0ubuntu1~bpo0-0ubuntu0.20.04.1",
            "binary_name": "rustfmt-1.80"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"
Ubuntu:Pro:22.04:LTS
cargo

Package

Name
cargo
Purl
pkg:deb/ubuntu/cargo?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.52.0-0ubuntu1
0.53.0-0ubuntu2
0.54.0-0ubuntu1
0.54.0-0ubuntu2
0.57.0+ubuntu-0ubuntu1
0.58.0-0ubuntu1
0.60.0ubuntu1-0ubuntu1~22.04.1
0.62.0ubuntu0libgit2-0ubuntu0.22.04.1
0.66.0+ds0ubuntu0.libgit2-0ubuntu0.22.04
0.67.1+ds0ubuntu0.libgit2-0ubuntu0.22.04.2
0.67.1+ds0ubuntu0.libgit2-0ubuntu0.22.04.2+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.67.1+ds0ubuntu0.libgit2-0ubuntu0.22.04.2+esm1",
            "binary_name": "cargo"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5223.json"