<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:01:00.055027+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08152</id>
    <title>bdu:2026-08152</title>
    <updated>2026-10-02T11:01:00.166583+00:00</updated>
    <content>bdu:2026-08152</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-5223</id>
    <title>BELL-CVE-2026-5223</title>
    <updated>2026-10-02T11:01:00.166624+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: rust, Alpaquita:25: rust, Alpaquita:stream: rust</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-5223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322250</id>
    <title>EUVD-2026-322250</title>
    <updated>2026-10-02T11:01:00.166657+00:00</updated>
    <content>EUVD-2026-322250</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-5223</id>
    <title>fkie_cve-2026-5223</title>
    <updated>2026-10-02T11:01:00.166671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-5223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jq42-7mfv-hm57</id>
    <title>GHSA-jq42-7mfv-hm57 — Cargo crates in third party registries can override the cached source of other crates</title>
    <updated>2026-10-02T11:01:00.166697+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: cargo</p>
<p>The Rust Security Response Team was notified that Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry.</p>
<p>This vulnerability is tracked as CVE-2026-5223. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.</p>
<p>## Overview</p>
<p>When building a crate, Cargo extracts its source code in a local cache (stored within `~/.cargo`), reusing it for any future build. Cargo includes protections to prevent any file from being extracted outside of the crate's own cache directory.</p>
<p>It was discovered that it's possible to craft a malicious tarball able to extract files one level below the crate's own cache directory. With the way the cache is structured, that allowed the malicious crate to override the cache of other crates belonging to the same registry.</p>
<p>## Mitigations</p>
<p>Rust 1.96.0, to be released on May 28th, 2026, will update Cargo to reject extracting *any* symlink within crate tarballs, regardless of whether they come from crates.io (which already forbids them) or third-party registries. Note that Cargo never added symlinks when running `cargo package` or `cargo publish`, so the impact of this should be minimal.</p>
<p>Users who are not able to upgrade to the most recent Rust version are recommended to audit the contents of t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jq42-7mfv-hm57"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-5223</id>
    <title>msrc_CVE-2026-5223 — Crates in third party registries can override the cached source of other crates</title>
    <updated>2026-10-02T11:01:00.166743+00:00</updated>
    <content>msrc_CVE-2026-5223</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-5223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:42923</id>
    <title>RHSA-2026:42923 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T11:01:00.166761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cargo: Cargo: Source code overwrite due to symlink mishandling in third-party registries cmov: cmov: Incorrect output due to improper zero-extension in aarch64 conditional move operations</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:42923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-5223</id>
    <title>UBUNTU-CVE-2026-5223</title>
    <updated>2026-10-02T11:01:00.166780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: rustc, Ubuntu:Pro:16.04:LTS: cargo, Ubuntu:Pro:16.04:LTS: rustc, Ubuntu:Pro:18.04:LTS: cargo, Ubuntu:Pro:18.04:LTS: rustc, Ubuntu:Pro:20.04:LTS: cargo, Ubuntu:Pro:20.04:LTS: rustc, Ubuntu:Pro:20.04:LTS: rustc-1.76, Ubuntu:Pro:20.04:LTS: rustc-1.77, Ubuntu:Pro:20.04:LTS: rustc-1.78 and 37 more</p>
<p>Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-5223"/>
  </entry>
</feed>
