** Also affects: cargo (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rust-tar (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rust-cargo-c (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.62 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rust-async-tar (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.74 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.76 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.77 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.78 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.79 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.80 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.81 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.82 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.83 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.84 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rust-astral-tokio-tar (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.85 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.88 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.89 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.91 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.92 (Ubuntu Focal)
Importance: Undecided
Status: New
** Also affects: rustc-1.93 (Ubuntu Focal)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2145764
Title:
CVE-2026-33056: Vendored tar crate can chmod arbitrary directories by
following symlinks
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cargo/+bug/2145764/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs