<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:48:22 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1894 — Moderate: rust-toolset:rhel8 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1894</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: cargo, AlmaLinux:8: cargo-doc, AlmaLinux:8: clippy, AlmaLinux:8: rls, AlmaLinux:8: rust, AlmaLinux:8: rust-analysis, AlmaLinux:8: rust-debugger-common, AlmaLinux:8: rust-doc, AlmaLinux:8: rust-gdb, AlmaLinux:8: rust-lldb and 6 more&lt;/p&gt;
&lt;p&gt;Rust Toolset provides the Rust programming language compiler rustc, the cargo build tool and dependency manager, and required libraries.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: rust (1.58.0). (BZ#2002883)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rust: Race condition in remove_dir_all leading to removal of files outside of the directory being removed (CVE-2022-21658)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: cargo, AlmaLinux:8: cargo-doc, AlmaLinux:8: clippy, AlmaLinux:8: rls, AlmaLinux:8: rust, AlmaLinux:8: rust-analysis, AlmaLinux:8: rust-debugger-common, AlmaLinux:8: rust-doc, AlmaLinux:8: rust-gdb, AlmaLinux:8: rust-lldb and 6 more&lt;/p&gt;
&lt;p&gt;Rust Toolset provides the Rust programming language compiler rustc, the cargo build tool and dependency manager, and required libraries.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: rust (1.58.0). (BZ#2002883)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rust: Race condition in remove_dir_all leading to removal of files outside of the directory being removed (CVE-2022-21658)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1894</guid>
    </item>
    <item>
      <title>bdu:2022-05167</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05167</link>
      <description>bdu:2022-05167</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05167</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-21658 — CVE-2022-21658 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-21658</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-21658</guid>
    </item>
    <item>
      <title>EUVD-2026-232839</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232839</link>
      <description>EUVD-2026-232839</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232839</guid>
    </item>
    <item>
      <title>fkie_cve-2022-21658</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21658</link>
      <description>&lt;p&gt;Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn&amp;#39;t otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don&amp;#39;t have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn&amp;#39;t otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don&amp;#39;t have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-21658</guid>
    </item>
    <item>
      <title>gsd-2022-21658</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-21658</link>
      <description>gsd-2022-21658</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-21658</guid>
    </item>
    <item>
      <title>ICSA-25-100-02 — Siemens SIDIS Prime</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-100-02</link>
      <description>&lt;p&gt;Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn&amp;#39;t otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don&amp;#39;t have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions. Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn&amp;#39;t otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don&amp;#39;t have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions. Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-100-02</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-21658 — Race condition in std::fs::remove_dir_all in rustlang</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-21658</link>
      <description>msrc_CVE-2022-21658</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-21658</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0149-1 — Security update for rust1.56</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0149-1</link>
      <description>&lt;p&gt;Security update for rust1.56&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rust1.56&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0149-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0149-1 — Security update for rust1.56</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0149-1</link>
      <description>&lt;p&gt;Security update for rust1.56&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rust1.56&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0149-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-21658</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21658</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: rustc, Ubuntu:Pro:16.04:LTS: rustc, Ubuntu:20.04:LTS: rustc&lt;/p&gt;
&lt;p&gt;Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn&amp;#39;t otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don&amp;#39;t have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: rustc, Ubuntu:Pro:16.04:LTS: rustc, Ubuntu:20.04:LTS: rustc&lt;/p&gt;
&lt;p&gt;Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn&amp;#39;t otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don&amp;#39;t have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21658</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0561 — Xerox FreeFlow Print Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0561</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0561</guid>
    </item>
  </channel>
</rss>
