The vendor has not yet reached a final affected or unaffected determination for these products.
- build-of-trustee/trustee-rhel9 as a component of Confidential Compute Attestation
- openshift-sandboxed-containers/osc-podvm-payload-rhel9 as a component of Confidential Compute Attestation
- cargo as a component of Red Hat Enterprise Linux 10
- clippy as a component of Red Hat Enterprise Linux 10
- rust-analyzer as a component of Red Hat Enterprise Linux 10
- rust-debugger-common as a component of Red Hat Enterprise Linux 10
- rust-doc as a component of Red Hat Enterprise Linux 10
- rust-gdb as a component of Red Hat Enterprise Linux 10
- rust-lldb as a component of Red Hat Enterprise Linux 10
- rust-src as a component of Red Hat Enterprise Linux 10
- rust-std-static as a component of Red Hat Enterprise Linux 10
- rust-std-static-aarch64-unknown-none-softfloat as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in the `cmov` component of RustCrypto. The aarch64 implementations of Cmov and CmovEq incorrectly assume that high bits are zero-extended when loading values smaller than a register. This can lead to incorrect output when certain high bits are set in a Cmov selector or in the u16 and i16 CmovEq implementations. This vulnerability could result in a low impact on data integrity.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
