The vendor explicitly identifies these products as affected by this CVE.
- cargo as a component of Red Hat Enterprise Linux 10
- clippy as a component of Red Hat Enterprise Linux 10
- rust-analyzer as a component of Red Hat Enterprise Linux 10
- rust-debugger-common as a component of Red Hat Enterprise Linux 10
- rust-doc as a component of Red Hat Enterprise Linux 10
- rust-gdb as a component of Red Hat Enterprise Linux 10
- rust-lldb as a component of Red Hat Enterprise Linux 10
- rust-src as a component of Red Hat Enterprise Linux 10
- rust-std-static as a component of Red Hat Enterprise Linux 10
- rust-std-static-aarch64-unknown-none-softfloat as a component of Red Hat Enterprise Linux 10
- rust-std-static-wasm32-unknown-unknown as a component of Red Hat Enterprise Linux 10
- rust-std-static-wasm32-wasip1 as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in libgit2. This vulnerability allows a remote attacker to create directories outside of the intended repository working tree. By crafting a malicious repository that specifies traversal components in a submodule path, applications initializing the submodule can be tricked into creating directories in arbitrary locations on the file system. This could lead to unintended file system modifications or potentially further compromise.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
