<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:28:58 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:4634 — Important: rust security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:4634</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: cargo, AlmaLinux:9: clippy, AlmaLinux:9: rust, AlmaLinux:9: rust-analysis, AlmaLinux:9: rust-analyzer, AlmaLinux:9: rust-debugger-common, AlmaLinux:9: rust-doc, AlmaLinux:9: rust-gdb, AlmaLinux:9: rust-lldb, AlmaLinux:9: rust-src and 5 more&lt;/p&gt;
&lt;p&gt;Rust Toolset provides the Rust programming language compiler rustc, the cargo build tool and dependency manager, and required libraries.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rust-cargo: cargo does not respect the umask when extracting dependencies (CVE-2023-38497)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: cargo, AlmaLinux:9: clippy, AlmaLinux:9: rust, AlmaLinux:9: rust-analysis, AlmaLinux:9: rust-analyzer, AlmaLinux:9: rust-debugger-common, AlmaLinux:9: rust-doc, AlmaLinux:9: rust-gdb, AlmaLinux:9: rust-lldb, AlmaLinux:9: rust-src and 5 more&lt;/p&gt;
&lt;p&gt;Rust Toolset provides the Rust programming language compiler rustc, the cargo build tool and dependency manager, and required libraries.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rust-cargo: cargo does not respect the umask when extracting dependencies (CVE-2023-38497)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:4634</guid>
    </item>
    <item>
      <title>bdu:2024-05823</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05823</link>
      <description>bdu:2024-05823</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05823</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-38497 — CVE-2023-38497 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-38497</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-38497</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-QJ53684 — Security fixes in rust 1.71.1-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-qj53684</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: rust&lt;/p&gt;
&lt;p&gt;Package rust version 1.71.1-r0 fixes 1 vulnerabilities: CVE-2023-38497&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: rust&lt;/p&gt;
&lt;p&gt;Package rust version 1.71.1-r0 fixes 1 vulnerabilities: CVE-2023-38497&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-qj53684</guid>
    </item>
    <item>
      <title>EUVD-2026-216657</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216657</link>
      <description>EUVD-2026-216657</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216657</guid>
    </item>
    <item>
      <title>fkie_cve-2023-38497</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-38497</link>
      <description>&lt;p&gt;Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one&amp;#39;s system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one&amp;#39;s system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-38497</guid>
    </item>
    <item>
      <title>GHSA-j3xp-wfr4-hx87 — Cargo not respecting umask when extracting crate archives</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j3xp-wfr4-hx87</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: cargo&lt;/p&gt;
&lt;p&gt;The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned CVE-2023-38497.&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;In UNIX-like systems, each file has three sets of permissions: for the user owning the file, for the group owning the file, and for all other local users. The &amp;#34;[umask][1]&amp;#34; is configured on most systems to limit those permissions during file creation, removing dangerous ones. For example, the default umask on macOS and most Linux distributions only allow the user owning a file to write to it, preventing the group owning it or other local users from doing the same.&lt;/p&gt;
&lt;p&gt;When a dependency is downloaded by Cargo, its source code has to be extracted on disk to allow the Rust compiler to read as part of the build. To improve performance, this extraction only happens the first time a dependency is used, caching the pre-extracted files for future invocations.&lt;/p&gt;
&lt;p&gt;Unfortunately, it was discovered that Cargo did not respect the umask during extraction, and propagated the permissions stored in the crate archive as-is. If an archive contained files writeable by any user on the system (and the system configuration didn&amp;#39;t prevent writes through other security measures), another local user on the system could replace o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: cargo&lt;/p&gt;
&lt;p&gt;The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned CVE-2023-38497.&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;In UNIX-like systems, each file has three sets of permissions: for the user owning the file, for the group owning the file, and for all other local users. The &amp;#34;[umask][1]&amp;#34; is configured on most systems to limit those permissions during file creation, removing dangerous ones. For example, the default umask on macOS and most Linux distributions only allow the user owning a file to write to it, preventing the group owning it or other local users from doing the same.&lt;/p&gt;
&lt;p&gt;When a dependency is downloaded by Cargo, its source code has to be extracted on disk to allow the Rust compiler to read as part of the build. To improve performance, this extraction only happens the first time a dependency is used, caching the pre-extracted files for future invocations.&lt;/p&gt;
&lt;p&gt;Unfortunately, it was discovered that Cargo did not respect the umask during extraction, and propagated the permissions stored in the crate archive as-is. If an archive contained files writeable by any user on the system (and the system configuration didn&amp;#39;t prevent writes through other security measures), another local user on the system could replace o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j3xp-wfr4-hx87</guid>
    </item>
    <item>
      <title>gsd-2023-38497</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-38497</link>
      <description>gsd-2023-38497</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-38497</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-38497 — Cargo not respecting umask when extracting crate archives</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-38497</link>
      <description>msrc_CVE-2023-38497</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-38497</guid>
    </item>
    <item>
      <title>OESA-2025-1236 — rust security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1236</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: rust&lt;/p&gt;
&lt;p&gt;Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety. This package includes the Rust compiler and documentation generator.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don&amp;amp;apos;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;amp;apos;s [`url.&amp;amp;lt;base&amp;amp;gt;.insteadOf`][1] setting), as that&amp;amp;apos;d cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server&amp;amp;apos;s public key is not already trusted. We recommend everyone to upgrade as soon as possible. (CVE-2022-46176)&lt;/p&gt;
&lt;p&gt;Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the sour…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: rust&lt;/p&gt;
&lt;p&gt;Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety. This package includes the Rust compiler and documentation generator.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don&amp;amp;apos;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;amp;apos;s [`url.&amp;amp;lt;base&amp;amp;gt;.insteadOf`][1] setting), as that&amp;amp;apos;d cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server&amp;amp;apos;s public key is not already trusted. We recommend everyone to upgrade as soon as possible. (CVE-2022-46176)&lt;/p&gt;
&lt;p&gt;Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the sour…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1236</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13101-1 — cargo1.71-1.71.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13101-1</link>
      <description>&lt;p&gt;cargo1.71-1.71.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cargo1.71-1.71.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13101-1</guid>
    </item>
    <item>
      <title>RHSA-2023:4651 — Red Hat Security Advisory: rust-toolset-1.66-rust security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:4651</link>
      <description>&lt;p&gt;rust-cargo: cargo does not respect the umask when extracting dependencies&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rust-cargo: cargo does not respect the umask when extracting dependencies&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:4651</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-38497</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38497</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: cargo, Ubuntu:Pro:18.04:LTS: cargo, Ubuntu:Pro:20.04:LTS: cargo, Ubuntu:Pro:22.04:LTS: cargo, Ubuntu:Pro:22.04:LTS: rust-cargo, Ubuntu:24.04:LTS: rust-cargo, Ubuntu:24.04:LTS: rustc&lt;/p&gt;
&lt;p&gt;Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one&amp;#39;s system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: cargo, Ubuntu:Pro:18.04:LTS: cargo, Ubuntu:Pro:20.04:LTS: cargo, Ubuntu:Pro:22.04:LTS: cargo, Ubuntu:Pro:22.04:LTS: rust-cargo, Ubuntu:24.04:LTS: rust-cargo, Ubuntu:24.04:LTS: rustc&lt;/p&gt;
&lt;p&gt;Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one&amp;#39;s system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38497</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2062 — Red Hat Enterprise Linux (Rust): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Die…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2062</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2062</guid>
    </item>
  </channel>
</rss>
