openSUSE-SU-2026:22016-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:22016-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:22016-1
Upstream
CVE (16)
Related
Published
2026-10-02T19:31:21Z
Modified
2026-10-03T17:00:03Z
Summary
Security update for rustup
Details

This update for rustup fixes the following issues:

  • CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243862).
  • CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249008).
  • CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (bsc#1274144).
  • CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257902).
  • CVE-2026-41676: openssl: Deriver:derive and PkeyCtxRef:derive can overflow short buffers on OpenSSL 1.1.1 (bsc#1270186).
  • CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270619).
  • CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270644).
  • CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270795).
  • CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270870).
  • CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270521).
  • CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate (bsc#1270874).
  • CVE-2026-45784: openssl: out-of-bounds write in CipherCtxRef::cipher_update_inplace for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270989).
  • CVE-2026-93599: rustls-webpki: panic via empty BIT STRING (bsc#1282217).
  • CVE-2026-93600: rustls-webpki: name constraints URI validation bypass (bsc#1282217).
  • CVE-2026-93601: rustls-webpki: name constraint bypass (bsc#1282217).
  • CVE-2026-93602: rustls-webpki: CRL revocation check bypass (bsc#1282217).
  • rust-shlex: Multiple issues involving quote API (RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032).

Changes for rustup:

  • Update to version 1.29.1~0:
  • dist(rustup-init/sh): update commit shasum in help string
  • style(bin/rustup-init): reformat code
  • docs(changelog): update for v1.29.1 stable release
  • warn how to switch away from the deprecated complete profile
  • fix(cli/help): fix wording in rustup run --help
  • ci(docker/android): stop building OpenSSL
  • refactor(cli/docs): use tracing for docs opening status messages
  • refactor(self-update): rename Windows uninstall registry helpers
  • feat(test): isolate Windows registry state per test
  • docs(dev-guide): mention how to support new compilation targets
  • Fix funding link
  • chore(deps): lock file maintenance
  • refactor(cli/self-update): move current_install_opts() to InstallOpts::display()
  • refactor(cli/self-update): move process out of InstallOpts
  • fix(cli/self-update): postpone initialization of Cfg in setup_mode
  • refactor(cli/self-update): take Process in check_existence_of_settings_file()
  • fix(settings): prevent creating new file with SettingsFile::read_settings()
  • test(cli-inst-interactive): test file creation on cancelled installation
  • refactor(toolchain/names): inline validate() aliases into FromStr
  • refactor(toolchain/names): rename validate() to normalize_name()
  • fix minor typos
  • www: align copy icon
  • refactor(toolchain/names)!: remove try_from_str!()
  • refactor(toolchain/names)!: remove from_variant!()
  • Add rustup doc --serve to serve docs over local HTTP
  • Move doc() and man() into a new docs module
  • chore(github): comment out instructions in PR template
  • docs(dev-guide): reapply abandoned changes from #4970
  • Add riscv64 unknown linux musl support
  • fix(deps): update rust crate enum-map to v3
  • refactor(cli/self-update)!: rename install() to InstallOpts::install()
  • refactor(cli/self-update)!: rename maybe_install_rust() to InstallOpts::install_rust()
  • refactor(cli/self-update)!: rename InstallOpts::install() to InstallOpts::select_toolchain()
  • refactor(toolchain/names)!: make more clones during conversions explicit
  • refactor(cli/self-update): move message templates to mod msg
  • style(cli/self-update): reorganize imports
  • Add pull request template linking to the dev guide
  • doc: add AI policy to the dev guide
  • ci(dist): ensure pushing to dev-static on stable update
  • test(toolchain): add a test case for rustup toolchain install --override
  • feat(toolchain): add --default flag to rustup toolchain install
  • fix(toolchain): inline use of set_override
  • Add Enzyme to the list of rustup components
  • fix: repair toolchains without an installed manifest
  • refactor: expose the installed manifest path
  • Docs: Remove i686 set default-host example
  • fix(self-update): only remove complete profile lines
  • chore(deps): bump platforms to 4.1.0
  • chore(deps): remove pinned openssl-src
  • refactor: replace cfg_if!{} with cfg_select!{}
  • fix: Lock state file updates
  • Fix Rust 1.97 clippy warnings
  • uninstalls toolchains prior to deleting the rustup home folder
  • Take semver-compatible dependency updates
  • Upgrade platforms to 4
  • docs: update CHANGELOG for v1.29.1
  • Lock file maintenance
  • Remove Windows special case from can_run
  • diskio: drop unnecessary constructor wrapper
  • diskio: rename _IncrementalFileState to FileState
  • diskio: inline IncrementalFileState type alias
  • Minimize API visibility
  • toolchain: streamline validate() implementations
  • toolchain: avoid internal cloning
  • dist: drop unused conversion impl
  • dist: keep impls with type definitions
  • Don't hide allocations inside From impls
  • toolchain: drop impls for &String
  • Warn on clippy::or_fun_call
  • Warn on clippy::needless_by_ref_mut
  • Warn on clippy::redundant_clone
  • Warn on clippy::manual_let_else
  • Warn on clippy::use_self
  • errors: box ToolchainDesc in RustupError variants
  • errors: box Manifest in RequestedComponentsUnavailable variant
  • No (more) need to allow clippy::arc_with_non_send_sync
  • Replace use of FnMut trait objects with custom trait
  • test(cli/self-upd): use direct arg0 override for as_rustup_setup()
  • chore(deps): update actions/cache action to v6
  • ci(windows): add support for aarch64-pc-windows-gnullvm target
  • ci(windows): refine MSVC/MINGW job step predicates
  • chore(deps): update actions/checkout action to v7
  • fix(deps): update rust crate itertools to 0.15
  • fix(progress): use the prefix placeholder instead of msg for component name
  • rustup: warn when no toolchain or default is configured
  • errors: extract default stable hint
  • feat(toolchain): make the "installed" text of a toolchain install green
  • Add aarch64-unknown-freebsd
  • chore: address linter warnings
  • chore(deps): bump to semver-compatible versions
  • Add funding links
  • ci(docker/freebsd): bump clang version to freebsd14
  • ci(freebsd): use FreeBSD 14.0 for full CI
  • chore(deps): update curl
  • feat(cli/rustup-mode): warn about auto-installation in some subcommands
  • refactor(config): accept Cfg in EnsureInstalled::warn_auto_install()
  • test(cli/rustup-mode): test auto-installation on to-be-deprecated subcommand
  • dist: move display_name() before other methods that it calls
  • chore(gitignore): add .cargo/config.windows-cross.toml to gitignore
  • docs(dev-guide): update platform-specific code guidance
  • docs(dev-guide): mention rust-analyzer support for Windows-specific code on Unix
  • docs(dev-guide): mention how to lint Windows-specific code on Unix
  • chore(config): add example config for cross checking and rust-analyzer
  • chore: add rust-analyzer example config
  • Display the full names of targets not matching the host target tuple
  • docs(dev-guide/tips-and-tricks): mention the RUSTUP_FORCE_ARG0='rustup' cargo alias
  • build(cargo): add cargo alias for RUSTUP_FORCE_ARG0='rustup'
  • docs: rename the repath helper variable
  • Remove double buffering when extracting archives
  • refactor(toolchain/distributable): return EnsureInstalled<> from DistributableToolchain::install()
  • docs(dev-guide/coding-standards): adapt style guide from rustls
  • fix(deps): update opentelemetry
  • feat(config): warn user if auto-install is enabled
  • refactor(config): return EnsureInstalled<> from more functions
  • refactor(config): extract EnsureInstalled<> wrapper type
  • test: make tests agnostic to external RUSTUP_AUTO_INSTALL and RUST_RECURSION_COUNT
  • test(dist): fail v2 manifest update when manifest disagrees with .sha256
  • fix(dist): propagate v2 manifest checksum failure instead of reporting "unchanged"
  • Align shell setup comments in install message
  • feat(cli/self-update): refine wording of "already installed Rust" warning
  • chore(settings): rename default_host_triple to default_host_tuple and alias old name
  • chore(settings): add test to parse default_host_triple in toml
  • test(download): also scrub HTTP_PROXY in scrub_env()
  • chore: document legacy default host setting
  • chore: rename internal tuple constants
  • chore: rename partially "Triple" to "Tuple" to reflect the new terminology
  • fix(cli/rustup-mode)!: complete rustup show if active toolchain is not installed
  • refactor(cli/rustup-mode): postpone eval of active_toolchain_targets in show()
  • refactor(cli/rustup-mode): postpone eval of active_toolchain in show()
  • refactor(cli/rustup-mode): reduce rightward drift in show()
  • refactor(cli/rustup-mode): refine usage of stdout term and locks in show()
  • feat(config): add Cfg field to force-disable auto-installation
  • Provide --yes alias for -y flag consistently
  • refactor(tests): rename triple to tuple
  • refactor: bulk rename triple to ruple
  • refactor: rename get_default_host_triple to default_host_tuple
  • test(download): support more feature flag combinations
  • docs: fix the FileBuffer::clear doc comment wording
  • docs: fix plural of VM in coding standards
  • fix(dist): bulk rename triple to tuple for variables and messages
  • refactor(dist): rename PartialTargetTriple to PartialTargetTuple
  • refactor(dist): rename triple module to target_tuple
  • refactor: remove PartialToochainDesc::has_triple() in favor to PartialTargetTriple::is_empty()
  • refactor(dist): rename TargetTriple to TargetTuple
  • fix(self-update): rename triple to tuple in self_update
  • dist: bump rustup version to v1.29.1
  • ci(linux/x64-musl): install missing libc dependencies
  • fix(tests): rename HOST_TRIPLE placeholder to HOST_TUPLE
  • fix(tests): rename this_host_triple() to this_host_tuple()
  • fix(init): rename triple to tuple to reflect the new terminology
  • fix(docs): rename triple to tuple to reflect the new terminology
  • chore(deps): update ubuntu docker tag to v26
  • Improve error message for incomplete toolchains
  • chore(deps): update bwoodsend/setup-winlibs-action action to v1.16
  • test(dist/manifest): use the reordered fixture in manifest_serialized_with_sorted_keys
  • docs: fix "initial" spelling in stylesheet variable
  • ci: powerpc64-unknown-linux-musl is now stable
  • style(cli/rustup-mode): address clippy warnings
  • docs(dev-guide): update release process with new backporting flow
  • docs: fix actions template README typo
  • Only show post-install instructions for currently installed shells
  • docs: fix Windows MSVC guide typo
  • Upgrade to rustls-platform-verifier 0.7
  • Make component removal best-effort and preserve single-error behavior
  • Use cc-rs to detect the default linker, instead of assuming cc
  • ci(test): add workflow_dispatch trigger on par with schedule
  • ci: fix incorrect contains() predicate
  • fix(dist/manifestation): fix log format when installing exactly 2 components
  • Allow rustup component add to install multiple components in one update #4787
  • fix(docs): correct link to no-self-update feature
  • ci: enable on all PR target branches
  • ci(backport): rename backport branches to release/*
  • feat(toolchain): run a pre-check before updating all toolchains
  • feat(install): accept an optional pre-fetched manifest when installing
  • fix(toolchain): extract manifest fetching out of show_dist_version()
  • fix(manifest): aggregate a manifest and its hash in a ManifestWithHash struct
  • fix: Reduce flickering by using set_move_cursor
  • ci(backport): add support for backporting
  • fix: install message misalignment.
  • refactor: extracted progress_style method for DownloadStatus
  • fix(deps): update rust crate sha2 to 0.11
  • chore(doc): Added comments for clarify the usage of Component::name Manifest::name and the short_name funcc accordingly.
  • refactor: Rename Component's name_in_manifest to name and short_name accordingly
  • self_update: show path to executable in case of updater failure
  • Revert "fix(ci/freebsd): install ca certs to prevent certificate-related issues"
  • ci: don't install protoc
  • Update to mdbook 0.5
  • ci(all-features): bump protoc version
  • fix(dist/manifestation): use full toolchain name in Update::unavailable_components()
  • style(dist/manifestation): merge imports
  • Fix zsh completion showing all PATH entries for +toolchain arg
  • fix(cli/proxy-mode): stop enforcing quiet: true
  • chore(deps/freebsd): downgrade libz-sys to v1.1.24
  • fix(ci/freebsd): install ca certs to prevent certificate-related issues
  • fix(rustup-init/sh): prevent passing --default-host twice
  • Avoid warning about the existence of a settings.toml on a fresh install
  • use tuple instead of triple for env overrides
  • Take platforms 3.9.0
  • Unpin tracing-subcriber
  • chore(deps): update aws-lc-rs and aws-lc-sys
  • docs(changelog): update release date for v1.29.0
  • docs(dev-guide/release-process): mention the CfT blog post
  • docs(changelog): update for v1.29.0 stable release
  • fix(cli): Style CLI errors in init mode
  • test: Add unknown arg init test
  • chore(deps): update actions/upload-artifact action to v7
  • refactor(www): simplify instruction css selector
  • feat(www): make copy button dark mode-aware
  • feat(www): move feedback text out of copy button
  • fix(www): apply filter to rust logo
  • feat(www): add dark mode
  • refactor(www): extract css variables
  • fix(cli/self-update): enforce a newline after check_updates()
  • refactor(cli/self-update): extract has_progress_bars in check_updates()
  • fix(cli/self-update): unify check_*update*()'s message formats
  • docs(downloads): fix the default number of RUSTUP_CONCURRENT_DOWNLOADS
  • feat(toolchain): add --override to override toolchain as soon as installed
  • fix(toolchain): improve logs when recovering from an interrupted installation
  • chore(deps): downgrade openssl-src to 300.5.4+3.5.4
  • style(download): clean up imports
  • fix(diskio): fall back to single-threaded unpacking when ram_budget < 512MB to avoid OOM on memory-constrained systems
  • test(downloads): check if an error is thrown if the server does not honor range
  • fix(downloads): check correct response when resuming from partial (reqwest)
  • fix(downloads): check correct response when resuming from partial (curl)
  • fix(deps): update rust crate toml to v1
  • fix(dist/manifest): sort keys when serializing Manifest
  • hack(ci/linux): disable BuildKit when building local images
  • chore(ci): use more distinctive local image names
  • Upgrade rand to 0.10
  • Upgrade snapbox to 1
  • Upgrade to anstream 1
  • fix(downloads): adjust error message for partial files in network failures
  • test(downloads): ensure that partial files are not removed when network fails
  • feat(downloads): do not delete partial download when network fails
  • fix(downloads): substitute DEK alias for DownloadError
  • chore(deps): update aws-actions/configure-aws-credentials action to v6
  • cli: introduce semantic exit code constants for rustup check
  • Add missing Windows SDK instructions
  • Add winget instructions to MSVC install page
  • Remove nu-string-interpolation $
  • Replace $nu.home-path with ~
  • feat(cli/rustup-mode): add "Exit status" section to rustup check --help
  • Add common commands section in help text
  • fix(cli/rustup-mode): improve exit code of rustup check
  • refactor(test)!: pass status code directly to SanitizedOutput
  • Add powerpc64-unknown-linux-musl support
  • fix: add copy_file_symlink_to_source for self-installation
  • fix: preserve symlinks in copy_dir instead of following them
  • feat(cli/rustup-mode): add doc --rustc-docs to open rustdoc for Rust internals
  • Remove the mixed singular/plural phrasing as "component(s)" instead, use "components" or "component". In the singular case also add the name of the component for more consistent messaging style with other info! outputs about single components.
  • fix(cli/rustup-mode): check for self updates for SelfUpdateMode::CheckOnly
  • test: Add test for sequential multi-toolchain uninstall
  • fix: directory removal race condition in toolchain uninstall
  • test(cli_v2): test error when missing many components on install
  • fix(dist): adjust printed newlines in components_missing_msg()
  • unified nightly disclaimer wording/styling; preserved distinct messages per scenario
  • Upgrade to reqwest 0.13
  • change test name to match new terminology
  • rename file to match new terminology
  • change 'target triple' to 'target tuple'
  • fix(toolchain): forbid toolchain names starting with +
  • cli: add doc --releases to open release notes
  • chore(deps): update actions/upload-artifact action to v6
  • chore(deps): update actions/cache action to v5
  • dist: use more concise API in helper function
  • dist: inline more logic into helper function
  • dist: give helper function a more meaningful name
  • dist: move helper function closer to usage site
  • docs(dev-guide): mention snapshot updating in release process
  • fix(toolchain): avoid unwrapping when parsing a toolchain name
  • fix(toolchain): change regex to reject leading zeros in toolchain name
  • docs(changelog): update for v1.29.0 beta release
  • dist: bump rustup version to v1.29.0
  • docs(changelog): add missing link references
  • test(static-roots): use a more compact syntax for raw binaries
  • test(static-roots): return Result from store_static_roots()
  • download: statically bundle relevant trust anchors
  • Added xonsh support
  • refactor(dist/manifestation): remove redundant redeclarations
  • docs(dist/download): remove outdated note on concurrent download progress reporting
  • fix(dist/download): align total_bytes fields in progress reporting UI
  • fix: default to GNU host in Cygwin/MSYS/MinGW environments (#4221)
  • chore(config): remove redundant imports
  • fix(dist/manifestation): print "downloading component" only on InstallEvents
  • fix(utils): downgrade panic to warning in delete_dir_contents_following_links()
  • chore(deps): update actions/checkout action to v6
  • Prepare for mdbook 0.5 migration
  • dist: make installation asynchronous
  • dist: make installations 'static
  • dist: take ownership of Manifestation
  • dist: store owned temp::Context in Transaction
  • dist: store temp::Context in DownloadCfg
  • dist: align progress bar elements
  • dist: track progress during unpacking
  • utils: drop unused reader tracking
  • process: fix refresh rate for progress bars
  • process: reduce duplication in ProgressDrawTarget setup
  • Yield references from Manifest::short_name()
  • Move Component name helpers to Manifest
  • dist: simplify ComponentBinary construction
  • dist: hoist creation of io_executor some more
  • Move unpack_ram() from dist to diskio
  • dist: hoist Executor creation up
  • dist: inline effective RAM limit calculation
  • dist: hoist environment variable extraction
  • dist: use logging for missing parent warnings
  • dist: clarify dependency on unpack RAM budget
  • diskio: clarify dependency on I/O thread count
  • dist: transfer ownership of component values
  • dist: take ownership of existing Components
  • dist: take ownership of toolchain name in update()
  • dist: take ownership of manifest in update()
  • dist: derive trivial initialization for Update
  • dist: rename Update::build_update() to new()
  • dist: linearize for-loop in Update::build_update()
  • dist: inline single-use function
  • dist: inline trivial helper function
  • dist: inline single-use tranaction change helpers
  • dist: store specific config bit in Transaction
  • chore(config): migrate config .github/renovate.json
  • dist: attach manifest download functions to DownloadCfg
  • rustup: unhide top-level install/uninstall commands
  • dist: move update_from_dist() to DistOptions::install_into()
  • Be more consistent about aliases for different subcommands
  • test: add test for rustup toolchain install --no-update
  • feat(rustup-mode): add no_update flag to rustup toolchain install
  • cli: prepare DistOptions in advance
  • dist: inline trivial wrapper function
  • cli: inline single-use update_all_channels() helper
  • config: simplify update_all_channels()
  • dist: deduplicate DistOptions initialization
  • dist: avoid recomputing dist root URL
  • dist: simplify tracing instrumentation
  • install: take ownership in InstallMethod::install()
  • dist: move DistributableToolchain::install() up
  • dist: clarify when update_hash is available
  • cli: avoid dropped temporary
  • Take semver-compatible dependencies
  • dist: install while downloading
  • dist: store more context in ComponentBinary
  • dist: yield self when download is complete
  • dist: move URL alteration logic into DownloadCfg method
  • Apply suggestions from clippy 1.91
  • refactor(check): Consolidate use_colors checks
  • fix(check): Use Cargo's colors
  • refactor(check): Make calls more consistent
  • dist: drop another layer of abstraction
  • dist: store package directory once
  • dist: inline short single-use function
  • dist: discard unnecessary abstraction layer
  • chore(deps): update actions/upload-artifact action to v5
  • fix(cli/rustup-mode): add missing self-update in rustup toolchain install
  • refactor(cli/self-update): move self_update() to SelfUpdateMode::update()
  • refactor(cli/rustup-mode): pass self-update predicates into self_update()
  • refactor(cli/self-update): import utils::ExitCode
  • rustup: tweak update check output style
  • fix(list): Match show command's styling
  • test(list): Add UI test
  • fix(toolchain): Have 'list' match 'show's styling
  • refactor(toolchain): Order logic by display order
  • refactor(toolchain): Use string interpolation
  • test(toolchain): Show list's behavior
  • fix(update): Match 'cargo update's colors
  • refactor(update): Centralize style knowledge
  • test: Cover different show_channel_update cases
  • fix(check): Subject check to RUSTUP_TERM_COLOR
  • test(check): Show current style
  • fix: Use HEADER styling in 'rustup show'
  • chore: Update clap-cargo
  • test: Demonstrate show's behavior
  • test(process): Allow forcing color on
  • test(process): Ensure non-locked writes are stripped of ANSI escape codes
  • cli: update uninstall_removes_source_from_rcs to mirror uninstall_doesnt_modify_rcs_with_no_modify_path
  • cli: add tests for rustup self uninstall --no-modify-path
  • cli: add rustup self uninstall --no-modify-path
  • cli: add help text for rustup self uninstall -y
  • fix(cli/help): change indentation of discussions to 2 spaces
  • fix(cli/help): adjust help text for rustup install
  • feat(cli/help): add toolchain install tips to rustup update's discussion
  • feat(cli/help): discuss rustup toolchain install
  • style: Remove wildcard imports
  • progress: modify progress bar's states to be column-aligned
  • installations: handle installation of components through progress bars
  • feat(cli): Add a sub-heading style for 'completion' Help Discussion
  • feat(cli): Have Help Discussions match rest of CLI Help
  • feat(cli): Add color to clap help/errors
  • refactor(cli): Switch help text to functions
  • cli: propagate ActiveSource from the top
  • cli: upgrade error events to ERROR level
  • cli: inline Cfg::active_rustc_version()
  • cli: extract display_version() from rustup main()
  • cli: inline Cfg::resolve_local_toolchain()
  • cli: inline Cfg::resolve_toolchain()
  • config: extract setting of toolchain override in rustup help mode
  • cli: avoid Cfg construction indirection
  • config: privatize some Cfg fields
  • config: drop trivial Cfg setters
  • Expand RUSTUP_TOOLCHAIN_SOURCE's documentation
  • refactor(installation): extract installation of a component into a separate function
  • bin: clean up imports
  • cli: rename CLIError to CliError
  • config: rename OverrideDB to OverrideDb
  • dist: clean up unnecessary qualification
  • test: Replace trycmd with snapbox
  • chore: Update snapbox
  • Update the default Windows SDK version
  • refactor(log): Single source RUSTUP_TERM_COLOR
  • style: Encourage using existing imports
  • process: avoid fine-grained locking for logs
  • process: discard unnecessary layer of synchronization
  • process: inline TerminalInnerLocked
  • process: replace unsafe code with safe equivalent
  • process: extract color_choice() method
  • process: extract is_a_tty value
  • process: inline StreamSelector::is_a_tty()
  • process: inline TestWriterLock
  • Implement RUSTUP_TOOLCHAIN_SOURCE with new Display impl
  • Move Display impl to to_reason()
  • Rename ActiveReason to ActiveSource
  • dist: simplify DownloadStatus setup
  • dist: decentralize download status
  • dist: postpone creation of ComponentBinary values
  • dist: extract DownloadStatus type
  • dist: call DownloadTracker methods directly
  • dist: drop unnecessary Notifier layer
  • dist: replace PackageContext with DownloadCfg
  • refactor: Directly apply styling
  • refactor: Don't bother grabbing lock for tests
  • refactor: Replace termcolor with anstream
  • refactor: Move style building out of ColorableTerminal
  • refactor: Migrate to anstyle for color definitions
  • fix(www): removes www subdomain from all rust-lang.org urls
  • dist: move Notification into dist::download
  • notifications: remove unused Display impl
  • dist: move Notifier into DownloadCfg
  • cli: build Cfg earlier in setup mode
  • dist: reuse existing DownloadCfg in update_v1()
  • dist: move dist_root out of DownloadCfg
  • dist: drop unused Clone derives
  • dist: drop Copy derive from DownloadCfg
  • dist: move Notifier and DownloadTracker into dist::download
  • dist: inline DownloadCfg test setup
  • download: move File items down
  • download: extract DownloadCfg initialization from Cfg
  • config: discard pointless method argument
  • cli: rename DownloadTracker::new_with_display_progress() to new()
  • notifications: log directly from DownloadTracker
  • notifications: log directly on bad download checksums
  • notifications: log directly when reusing downloaded files
  • notifications: log directly on buffer size changes
  • Update platforms to 3.7.0
  • notifications: log directly on duplicate toolchain files
  • notifications: log directly on metadata upgrades that remove toolchains
  • notifications: log directly when reading metadata version
  • notifications: log directly when metadata upgrade is not needed
  • notifications: log directly when upgrading metadata version
  • notifications: log directly when uninstalling toolchains
  • notifications: log directly when toolchain is up to date
  • notifications: log directly when toolchain has been installed
  • notifications: log directly when installing toolchains
  • notifications: log the toolchain directory directly
  • notifications: log directly when using existing toolchains
  • notifications: log directly when looking for toolchains
  • notifications: log directly when setting auto-self-update mode
  • notifications: log directly when setting profile
  • notifications: log directly when setting overrides
  • notifications: use human-friendly log format for temp file deletions
  • notifications: use human-friendly log format for directory deletions
  • notifications: use human-friendly log format for retrying renames
  • notifications: use human-friendly log format for path canonicalization
  • cli: drop unnecessary generics
  • process: import instead of qualifying ColorableTerminal
  • process: hide internal structure
  • process: don't re-export external items
  • process: rename terminalsource to terminal_source
  • process: rename filesource to file_source
  • process: re-order items in terminalsource module
  • feat(cli/self-update): add support for PowerShell on Unix systems
  • refactor: Remove unused traits
  • refactor: Directly use ColorableTerminal
  • refactor: Simplify working with ColorableTerminal
  • fix(process): Ensure stdout/stderr lock is held across calls
  • refactor(process): Centralize Write bookkeeping
  • docs(changelog): describe default profile change during auto-install
  • Fix typo in clitools.rs comment
  • ci(docs): fix local doc branch name
  • Move the default branch from master to main
  • Upgrade opentelemetry dependencies
  • ci: use macOS Intel runners
  • notifications: log directly when setting the default toolchain
  • notifications: log directly when setting auto install mode
  • notifications: log directly when resuming partial downloads
  • notifications: log directly when downloading files
  • notifications: log directly when removing stray hash files
  • notifications: log directly when skipping components
  • notifications: log directly on missing components
  • notifications: log directly when downloading legacy manifests
  • notifications: log directly for downloaded manifests
  • notifications: log directly for manifest downloads
  • notifications: log directly when removing components
  • notifications: log directly when installing components
  • notifications: log directly after failing to determine memory limit
  • notifications: log directly when hash file not found
  • notifications: log directly when failing to update hash file
  • notifications: log directly when component is already installed
  • notifications: log directly for valid checksums
  • notifications: log directly when using download backends
  • chore: avoid trailing whitespace in error message
  • refactor: Switch logging to anstyle
  • refactor: Remove unused ColorableTerminal::carriage_return
  • notifications: privatize Notification type
  • notifications: log directly on creating temp files
  • notifications: log directly on temp root creation
  • notifications: log directly on file deletions
  • notifications: log directly on directory deletions
  • notifications: log directly about non-fatal errors
  • notifications: log directly about rolling back changes
  • notifications: log directly for retrying renames
  • notifications: log directly when removing directories
  • notifications: log directly when copying directories
  • notifications: log directly when linking directories
  • notifications: log directly when path canonicalization fails
  • notifications: log directly when creating directories
  • tests: use DistContext for dist::components tests
  • tests: move DistContext into library
  • tests: deduplicate distribution installation tests
  • notifications: tweak style
  • Inline utils Notification variants into top-level Notification
  • Inline dist Notification variants into top-level Notification
  • Inline dist::temp::Notification variants into top-level Notification
  • dist: remove temp::Notification variant from dist::Notification
  • dist: extract URL alteration from download() method
  • dist: detach download_component() from Manifestation
  • dist: introduce ComponentBinary type
  • dist: avoid passing through arguments
  • dist: avoid unnecessary type annotations
  • dist: avoid cloning components Vec
  • refactor: remove redundant references
  • dist: simpify casting to trait object
  • dist: deduplicate decompression setup code
  • cli: move more self update logic into self_update module
  • refactor(dist/manifestation): remove redundant .to_string()
  • Remove unneeded paranthesees
  • Fix link in the bug reporting template
  • ci(all-features/windows): update OPENSSL_LIB_DIR for OpenSSL v3 compatibility
  • docs(dev-guide): improve suggestion for overriding arg0
  • docs(dev-guide): mention the arg0 override trick on welcome page
  • docs(README): link CI status badge to GitHub Actions panel
  • feat(dist/manifestation): adjust default concurrent downloads when installing toolchains
  • feat(cli/rustup-mode): check updates for all channels unless RUSTUP_CONCURRENT_DOWNLOADS is set to 1
  • refactor: rename num_channels to concurrent_downloads
  • fix: fix hang by preventing stream.buffered(0) in concurrent downloads
  • test(dist/manifestation): extract TestContext::*with_env()
  • refactor(download): use NonZero instead of NonZeroU64
  • refactor(process): remove redundant .context() in Process::concurrent_downloads()
  • chore(deps/renovate): group version bumps for windows-rs crates
  • Upgrade windows crates
  • fix(cli/rustup_mode): use ASCII-compatible spinner
  • chore(deps): update aws-actions/configure-aws-credentials action to v5
  • feat(install): warn if default linker (cc) is missing; add respective test case
  • Remove hardcoded dependency to the master branch
  • feat(downloads): delay the reappearance of the progress bar when retrying a download
  • fix(downloads): correct faulty behavior when a download fails
  • fix(downloads): correct faulty output when retrying a download
  • feat(self_update): add tcsh shell support to cli #3413
  • Replace non_empty_env_var() with Process::var_opt()
  • fix(downloads): report real elapsed time of a component downloads instead of cumulative
  • Treat empty environment variables as unset
  • fix(downloads): honor the RUSTUP_CONCURRENT_DOWNLOADS by always having "n" concurrent downloads
  • chore(deps): disable default features for zstd
  • feat(downloads): introduce RUSTUP_CONCURRENT_DOWNLOADS to control concurrency
  • ci(check): make installation of taplo-cli faster
  • fix(notifications): delete unnecessary Download(Pop/Push)Unit notifications
  • fix(downloads): extract closure for downloading a component into a separate function
  • feat(downloads): concurrently download components
  • fix(downloads): add a comment to justify the unwrap on .get() of OnceLock
  • chore(deps): update actions/checkout action to v5
  • fix(download_timeout): introduce RUSTUP_DOWNLOAD_TIMEOUT for overriding download timeout
  • fix(downloads): substitute the LazyLock for a OnceLock
  • feat(rustup_mode): revise help message
  • feat: improve error message for rustup which
  • test: detach snapshots from component installation order
  • feat(download_tracker): refactor in favor of indicatif
  • feat(process): create a ProgressDrawTarget (for indicatif) inside the Process
  • fix(rustup-init/sh): avoid hw.optional.*: 1 stdout in macOS arch check
  • hack(cli/common): suppress host emulation warnings in rustup's own CI
  • fix(test/clitools): pass RUSTUP_CI to in-process tests
  • ci(macos): run x64 workflows with Rosetta 2
  • docs(user-guide/environment-variables): clarify the unit of RUSTUP_UNPACK_RAM
  • docs(user-guide/environment-variables): unify description style
  • docs(user-guide/environment-variables): update description of RUSTUP_IO_THREADS
  • Limit Tokio worker threads to I/O thread count
  • Use manual Tokio runtime setup
  • Attach io_thread_count() to Process
  • Always consider RUSTUP_IO_THREADS as input for thread count
  • utils: express io_thread_count() in a simpler way
  • opt(err): show renaming file error source
  • Set a maximum thread limit for remove_dir_all
  • fix(toolchain/distributable): refine handling of known targets with no prebuilt artifacts
  • fix(ci/fetch-rust-docker): update comments
  • fix(ci/docker): update CC name for powerpc64le-unknown-linux-gnu
  • Extract self_update() from update_all_channels()
  • Show channel updates even if self update is not permitted
  • Remove Cargo feature indirection
  • Move Cfg::get_self_update_mode() to SelfUpdateMode::from_cfg()
  • Replace trivial enum with bool
  • feat(updates): introduce RUSTUP_TERM_WIDTH to override terminal width
  • feat(updates): introduce RUSTUP_TERM_PROGRESS_WHEN to toggle the progress bars
  • Limit the default number of I/O threads
  • Bump toml to 0.9
  • feat(updates): check for updates concurrently
  • feat(terminal): implement the TermLike trait for ColorableTerminal
  • chore: use match ergonomics in favor of explicit refs
  • refactor(download/curl): use early returns in download()
  • chore(cli/rustup_mode): merge std imports
  • chore(cli/rustup-mode): import std::io
  • chore: fix new clippy warnings
  • fix(ci/run): specify target triple for bindgen-cli installation
  • feat(www): improve "copy" button style compatibility with Chromium
  • ci(run): install codegen-cli with cargo-binstall
  • docs: replace Discord links
  • Block broken snap curl
  • Upgrade to windows-sys 0.60
  • Emphasize that llvm-tools dist component is not subject to compiler stability guarantees
  • docs(README): update CI status badge
  • Fix rustup-init.sh cputype check for sparcv9
  • add Solaris support
  • test(clitools)!: remove all deprecated .expect_*() APIs
  • test(clitools)!: privatize Config::run()
  • test: migrate remaining uses of .run() to .expect() APIs
  • test(clitools): extract Assert::redact()
  • test: simplify .display().to_string() in .extend_redactions()
  • test(cli_misc): bring back missing assertions
  • Update help.rs: bash completions instructions (#1)
  • docs(user-guide): fix typo
  • docs(dev-guide): update the section on clippy lints
  • docs(dev-guide): mention test helpers and Assert
  • docs(test/clitools): add docs for Assert
  • Upgrade to rustls-platform-verifier 0.6
  • test(cli-v2): migrate to .expect() APIs
  • test(cli-misc): migrate to .expect() APIs
  • fix(toolchain): fix proxy fallback notification format on Windows
  • test(cli-v1): migrate to .expect() APIs
  • test(download): serialize tests with proxy-sensitive URLs
  • test(cli-rustup): migrate to .expect() APIs
  • test(clitool): add Assert::remove_redactions()
  • test(clitools): allow OsStr-like args in Config::expect*()
  • Fix CI image names for downloading ARM and PowerPC artifacts
  • Update platforms to 3.6
  • test(cli-exact): migrate to .expect() APIs
  • Avoid swallowing errors in show()
  • Simplify target processing logic
  • Inline returned bindings
  • Increase Windows main thread stack size to 2mb
  • test(cli-inst-interactive): migrate to .expect() APIs
  • Unset RUSTUP_AUTO_INSTALL for tests
  • test(cli-paths): migrate to .expect() APIs
  • test(cli-exact): use the new [CURRENT_VERSION] redaction
  • test(cli-self-upd): migrate to .expect() APIs
  • Tweak list_items() docstring
  • Leverage bool::then_some() to simplify some code
  • Avoid intermediate allocation in listing
  • test(custom-toolchains): target list now can display the installed targets
  • feat(custom-toolchains): target and component list working on custom toolchains
  • Skip manifest loading if there are no components/targets to check
  • fix(deps): update rust crate opener to 0.8.0
  • rustup check: set exit status based on available updates
  • rustup check: adopt no-self-update logic
  • feat(self_update): add proxy sanity checks
  • style(test): qualify uses of snapbox::str![]
  • refactor(test): migrate some tests to .expect() APIs
  • chore(test): deprecated old APIs overlapping with the new ones
  • refactor(test): add new .expect()-based testing APIs
  • test(custom-toolchains): using show on a custom toolchain without a components file
  • test(custom-toolchains): add test to showcase that the issue was solved
  • feat(custom-toolchains): rustup show now reporting installed targets
  • tests: print diffs on test failures
  • Log versions during self updates
  • Fix cargo lints on Windows
  • toolchain: hoist binary name conditionals out of fallback functions
  • refactor(test): replace TempDir::into_path() with TempDir::keep()
  • refactor(test/clitools): use globally-defined tempdir_in_with_prefix()
  • feat(toolchain): notify the user when proxy fallback is activated
  • feat(toolchain): consider external rust-analyzer when calling a proxy
  • refactor(toolchain): move predicates into Toolchain::maybe_do_cargo_fallback()
  • refactor(toolchain): privatize Toolchain::maybe_do_cargo_fallback()
  • deps: update aws-lc-rs to 1.13.1
  • docs(changelog): mirror changes from the release announcement, take 2
  • Deprecate native-tls as well
  • Enable HTTP/2 support for reqwest download backend
  • Emit tracing events from log facade calls
  • download: show Debug representation for errors
  • Avoid repeated globals in tracing events
  • Log original download errors immediately
  • feat(cli/rustup-mode): add aliases to rustup component remove
  • Switch flate2 to use the zlib-rs backend
  • Hardlink proxies if symlinks aren't reachable
  • Add powerpc64le-unknown-linux-musl support
  • Add toolchain_name to not installed bail msg
  • Warn about using curl
  • Drop workspace indirection
  • Fold download crate back into rustup
  • download: merge integration test files
  • Test CARGO environment replacement
  • Update CARGO env var if it is a rustup proxy
  • Tweak toolchain subcommand help text
  • Move toolchain and default commands first
  • show toolchain paths in rustup show -v output
  • refactor(cli/self-update): save allocations in Nu::rcfiles()
  • fix(cli/self-update)!: stop appending to env.nu due to deprecation
  • fix(cli/self-update): consider Windows paths in Nushell suggestions
  • refactor(cli/self-update): use path add in env.nu template
  • fix(cli/self-update): use interpolated string in env.nu template
  • Upgrade dependencies
  • docs(user-guide/environment-variables): document RUSTUP_VERSION
  • feat(rustup-init/sh): allow setting RUSTUP_VERSION during installation
  • feat(cli/self-update): allow setting RUSTUP_VERSION for arbitrary downgrades
  • feat(test/clitools): add Config::expect_ok_ex_env()
  • fix(errors)!: improve error messages for RustupError::ToolchainNotInstalled
  • Add set auto-install disable
  • Use cursor: pointer for copy button on website
  • fix(dist): refine suggestions about missing targets
  • Append Windows bin directory to PATH by default
  • Remove validation for custom toolchains when reading rust-toolchain.toml
  • document RUSTUP_AUTO_INSTALL
  • Fix build script cargo instructions
References

Affected packages

openSUSE:Leap 16.0 / rustup

Package

Name
rustup
Purl
pkg:rpm/opensuse/rustup&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.29.1~0-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "rustup":  "1.29.1~0-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:22016-1.json"