OPENSUSE-SU-2026:22016-1
Vulnerability from csaf_opensuse - Published: 2026-10-02 19:31 - Updated: 2026-10-03 16:17Summary
Security update for rustup
Severity
Important
Notes
Title of the patch: Security update for rustup
Description of the patch: This update for rustup fixes the following issues:
- CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243862).
- CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249008).
- CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes
(bsc#1274144).
- CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion
(bsc#1257902).
- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1
(bsc#1270186).
- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-
openssl crate (bsc#1270619).
- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270644).
- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate
(bsc#1270795).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent
memory in rust-openssl crate (bsc#1270870).
- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate
(bsc#1270521).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate
(bsc#1270874).
- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-
openssl crate (bsc#1270989).
- CVE-2026-93599: rustls-webpki: panic via empty BIT STRING (bsc#1282217).
- CVE-2026-93600: rustls-webpki: name constraints URI validation bypass (bsc#1282217).
- CVE-2026-93601: rustls-webpki: name constraint bypass (bsc#1282217).
- CVE-2026-93602: rustls-webpki: CRL revocation check bypass (bsc#1282217).
- rust-shlex: Multiple issues involving quote API (RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032).
Changes for rustup:
- Update to version 1.29.1~0:
* dist(rustup-init/sh): update commit shasum in help string
* style(bin/rustup-init): reformat code
* docs(changelog): update for v1.29.1 stable release
* warn how to switch away from the deprecated complete profile
* fix(cli/help): fix wording in `rustup run --help`
* ci(docker/android): stop building OpenSSL
* refactor(cli/docs): use tracing for docs opening status messages
* refactor(self-update): rename Windows uninstall registry helpers
* feat(test): isolate Windows registry state per test
* docs(dev-guide): mention how to support new compilation targets
* Fix funding link
* chore(deps): lock file maintenance
* refactor(cli/self-update): move `current_install_opts()` to `InstallOpts::display()`
* refactor(cli/self-update): move `process` out of `InstallOpts`
* fix(cli/self-update): postpone initialization of `Cfg` in `setup_mode`
* refactor(cli/self-update): take `Process` in `check_existence_of_settings_file()`
* fix(settings): prevent creating new file with `SettingsFile::read_settings()`
* test(cli-inst-interactive): test file creation on cancelled installation
* refactor(toolchain/names): inline `validate()` aliases into `FromStr`
* refactor(toolchain/names): rename `validate()` to `normalize_name()`
* fix minor typos
* www: align copy icon
* refactor(toolchain/names)!: remove `try_from_str!()`
* refactor(toolchain/names)!: remove `from_variant!()`
* Add `rustup doc --serve` to serve docs over local HTTP
* Move doc() and man() into a new docs module
* chore(github): comment out instructions in PR template
* docs(dev-guide): reapply abandoned changes from #4970
* Add riscv64 unknown linux musl support
* fix(deps): update rust crate enum-map to v3
* refactor(cli/self-update)!: rename `install()` to `InstallOpts::install()`
* refactor(cli/self-update)!: rename `maybe_install_rust()` to `InstallOpts::install_rust()`
* refactor(cli/self-update)!: rename `InstallOpts::install()` to `InstallOpts::select_toolchain()`
* refactor(toolchain/names)!: make more clones during conversions explicit
* refactor(cli/self-update): move message templates to `mod msg`
* style(cli/self-update): reorganize imports
* Add pull request template linking to the dev guide
* doc: add AI policy to the dev guide
* ci(dist): ensure pushing to `dev-static` on `stable` update
* test(toolchain): add a test case for `rustup toolchain install --override`
* feat(toolchain): add `--default` flag to `rustup toolchain install`
* fix(toolchain): inline use of `set_override`
* Add Enzyme to the list of rustup components
* fix: repair toolchains without an installed manifest
* refactor: expose the installed manifest path
* Docs: Remove i686 `set default-host` example
* fix(self-update): only remove complete profile lines
* chore(deps): bump `platforms` to 4.1.0
* chore(deps): remove pinned `openssl-src`
* refactor: replace `cfg_if!{}` with `cfg_select!{}`
* fix: Lock state file updates
* Fix Rust 1.97 clippy warnings
* uninstalls toolchains prior to deleting the rustup home folder
* Take semver-compatible dependency updates
* Upgrade platforms to 4
* docs: update `CHANGELOG` for v1.29.1
* Lock file maintenance
* Remove Windows special case from `can_run`
* diskio: drop unnecessary constructor wrapper
* diskio: rename _IncrementalFileState to FileState
* diskio: inline IncrementalFileState type alias
* Minimize API visibility
* toolchain: streamline validate() implementations
* toolchain: avoid internal cloning
* dist: drop unused conversion impl
* dist: keep impls with type definitions
* Don't hide allocations inside From impls
* toolchain: drop impls for &String
* Warn on clippy::or_fun_call
* Warn on clippy::needless_by_ref_mut
* Warn on clippy::redundant_clone
* Warn on clippy::manual_let_else
* Warn on clippy::use_self
* errors: box ToolchainDesc in RustupError variants
* errors: box Manifest in RequestedComponentsUnavailable variant
* No (more) need to allow clippy::arc_with_non_send_sync
* Replace use of FnMut trait objects with custom trait
* test(cli/self-upd): use direct arg0 override for `as_rustup_setup()`
* chore(deps): update actions/cache action to v6
* ci(windows): add support for aarch64-pc-windows-gnullvm target
* ci(windows): refine MSVC/MINGW job step predicates
* chore(deps): update actions/checkout action to v7
* fix(deps): update rust crate itertools to 0.15
* fix(progress): use the `prefix` placeholder instead of `msg` for component name
* rustup: warn when no toolchain or default is configured
* errors: extract default stable hint
* feat(toolchain): make the "installed" text of a toolchain install green
* Add aarch64-unknown-freebsd
* chore: address linter warnings
* chore(deps): bump to semver-compatible versions
* Add funding links
* ci(docker/freebsd): bump `clang` version to `freebsd14`
* ci(freebsd): use FreeBSD 14.0 for full CI
* chore(deps): update `curl`
* feat(cli/rustup-mode): warn about auto-installation in some subcommands
* refactor(config): accept `Cfg` in `EnsureInstalled::warn_auto_install()`
* test(cli/rustup-mode): test auto-installation on to-be-deprecated subcommand
* dist: move display_name() before other methods that it calls
* chore(gitignore): add .cargo/config.windows-cross.toml to gitignore
* docs(dev-guide): update platform-specific code guidance
* docs(dev-guide): mention rust-analyzer support for Windows-specific code on Unix
* docs(dev-guide): mention how to lint Windows-specific code on Unix
* chore(config): add example config for cross checking and rust-analyzer
* chore: add rust-analyzer example config
* Display the full names of targets not matching the host target tuple
* docs(dev-guide/tips-and-tricks): mention the `RUSTUP_FORCE_ARG0='rustup'` cargo alias
* build(cargo): add `cargo` alias for `RUSTUP_FORCE_ARG0='rustup'`
* docs: rename the repath helper variable
* Remove double buffering when extracting archives
* refactor(toolchain/distributable): return `EnsureInstalled<>` from `DistributableToolchain::install()`
* docs(dev-guide/coding-standards): adapt style guide from rustls
* fix(deps): update opentelemetry
* feat(config): warn user if auto-install is enabled
* refactor(config): return `EnsureInstalled<>` from more functions
* refactor(config): extract `EnsureInstalled<>` wrapper type
* test: make tests agnostic to external `RUSTUP_AUTO_INSTALL` and `RUST_RECURSION_COUNT`
* test(dist): fail v2 manifest update when manifest disagrees with .sha256
* fix(dist): propagate v2 manifest checksum failure instead of reporting "unchanged"
* Align shell setup comments in install message
* feat(cli/self-update): refine wording of "already installed Rust" warning
* chore(settings): rename default_host_triple to default_host_tuple and alias old name
* chore(settings): add test to parse default_host_triple in toml
* test(download): also scrub `HTTP_PROXY` in `scrub_env()`
* chore: document legacy default host setting
* chore: rename internal tuple constants
* chore: rename partially "Triple" to "Tuple" to reflect the new terminology
* fix(cli/rustup-mode)!: complete `rustup show` if active toolchain is not installed
* refactor(cli/rustup-mode): postpone eval of `active_toolchain_targets` in `show()`
* refactor(cli/rustup-mode): postpone eval of `active_toolchain` in `show()`
* refactor(cli/rustup-mode): reduce rightward drift in `show()`
* refactor(cli/rustup-mode): refine usage of `stdout` term and locks in `show()`
* feat(config): add `Cfg` field to force-disable auto-installation
* Provide --yes alias for -y flag consistently
* refactor(tests): rename triple to tuple
* refactor: bulk rename triple to ruple
* refactor: rename get_default_host_triple to default_host_tuple
* test(download): support more feature flag combinations
* docs: fix the FileBuffer::clear doc comment wording
* docs: fix plural of VM in coding standards
* fix(dist): bulk rename triple to tuple for variables and messages
* refactor(dist): rename PartialTargetTriple to PartialTargetTuple
* refactor(dist): rename triple module to target_tuple
* refactor: remove PartialToochainDesc::has_triple() in favor to PartialTargetTriple::is_empty()
* refactor(dist): rename TargetTriple to TargetTuple
* fix(self-update): rename triple to tuple in self_update
* dist: bump `rustup` version to v1.29.1
* ci(linux/x64-musl): install missing libc dependencies
* fix(tests): rename HOST_TRIPLE placeholder to HOST_TUPLE
* fix(tests): rename this_host_triple() to this_host_tuple()
* fix(init): rename triple to tuple to reflect the new terminology
* fix(docs): rename triple to tuple to reflect the new terminology
* chore(deps): update ubuntu docker tag to v26
* Improve error message for incomplete toolchains
* chore(deps): update bwoodsend/setup-winlibs-action action to v1.16
* test(dist/manifest): use the reordered fixture in `manifest_serialized_with_sorted_keys`
* docs: fix "initial" spelling in stylesheet variable
* ci: powerpc64-unknown-linux-musl is now stable
* style(cli/rustup-mode): address clippy warnings
* docs(dev-guide): update release process with new backporting flow
* docs: fix actions template README typo
* Only show post-install instructions for currently installed shells
* docs: fix Windows MSVC guide typo
* Upgrade to rustls-platform-verifier 0.7
* Make component removal best-effort and preserve single-error behavior
* Use `cc-rs` to detect the default linker, instead of assuming `cc`
* ci(test): add `workflow_dispatch` trigger on par with `schedule`
* ci: fix incorrect `contains()` predicate
* fix(dist/manifestation): fix log format when installing exactly 2 components
* Allow rustup component add to install multiple components in one update #4787
* fix(docs): correct link to `no-self-update` feature
* ci: enable on all PR target branches
* ci(backport): rename backport branches to `release/*`
* feat(toolchain): run a pre-check before updating all toolchains
* feat(install): accept an optional pre-fetched manifest when installing
* fix(toolchain): extract manifest fetching out of `show_dist_version()`
* fix(manifest): aggregate a manifest and its hash in a `ManifestWithHash` struct
* fix: Reduce flickering by using `set_move_cursor`
* ci(backport): add support for backporting
* fix: install message misalignment.
* refactor: extracted `progress_style` method for DownloadStatus
* fix(deps): update rust crate sha2 to 0.11
* chore(doc): Added comments for clarify the usage of `Component::name` `Manifest::name` and the `short_name` funcc accordingly.
* refactor: Rename `Component`'s `name_in_manifest` to `name` and `short_name` accordingly
* self_update: show path to executable in case of updater failure
* Revert "fix(ci/freebsd): install ca certs to prevent certificate-related issues"
* ci: don't install protoc
* Update to mdbook 0.5
* ci(all-features): bump protoc version
* fix(dist/manifestation): use full toolchain name in `Update::unavailable_components()`
* style(dist/manifestation): merge imports
* Fix zsh completion showing all PATH entries for +toolchain arg
* fix(cli/proxy-mode): stop enforcing `quiet: true`
* chore(deps/freebsd): downgrade `libz-sys` to v1.1.24
* fix(ci/freebsd): install ca certs to prevent certificate-related issues
* fix(rustup-init/sh): prevent passing `--default-host` twice
* Avoid warning about the existence of a `settings.toml` on a fresh install
* use tuple instead of triple for env overrides
* Take platforms 3.9.0
* Unpin tracing-subcriber
* chore(deps): update `aws-lc-rs` and `aws-lc-sys`
* docs(changelog): update release date for v1.29.0
* docs(dev-guide/release-process): mention the CfT blog post
* docs(changelog): update for v1.29.0 stable release
* fix(cli): Style CLI errors in init mode
* test: Add unknown arg init test
* chore(deps): update actions/upload-artifact action to v7
* refactor(www): simplify instruction css selector
* feat(www): make copy button dark mode-aware
* feat(www): move feedback text out of copy button
* fix(www): apply filter to rust logo
* feat(www): add dark mode
* refactor(www): extract css variables
* fix(cli/self-update): enforce a newline after `check_updates()`
* refactor(cli/self-update): extract `has_progress_bars` in `check_updates()`
* fix(cli/self-update): unify `check_*update*()`'s message formats
* docs(downloads): fix the default number of `RUSTUP_CONCURRENT_DOWNLOADS`
* feat(toolchain): add `--override` to override toolchain as soon as installed
* fix(toolchain): improve logs when recovering from an interrupted installation
* chore(deps): downgrade `openssl-src` to 300.5.4+3.5.4
* style(download): clean up imports
* fix(diskio): fall back to single-threaded unpacking when `ram_budget` < 512MB to avoid OOM on memory-constrained systems
* test(downloads): check if an error is thrown if the server does not honor range
* fix(downloads): check correct response when resuming from partial (reqwest)
* fix(downloads): check correct response when resuming from partial (curl)
* fix(deps): update rust crate toml to v1
* fix(dist/manifest): sort keys when serializing `Manifest`
* hack(ci/linux): disable BuildKit when building local images
* chore(ci): use more distinctive local image names
* Upgrade rand to 0.10
* Upgrade snapbox to 1
* Upgrade to anstream 1
* fix(downloads): adjust error message for partial files in network failures
* test(downloads): ensure that partial files are not removed when network fails
* feat(downloads): do not delete partial download when network fails
* fix(downloads): substitute `DEK` alias for `DownloadError`
* chore(deps): update aws-actions/configure-aws-credentials action to v6
* cli: introduce semantic exit code constants for rustup check
* Add missing Windows SDK instructions
* Add winget instructions to MSVC install page
* Remove nu-string-interpolation `$`
* Replace $nu.home-path with ~
* feat(cli/rustup-mode): add "Exit status" section to `rustup check --help`
* Add common commands section in help text
* fix(cli/rustup-mode): improve exit code of `rustup check`
* refactor(test)!: pass status code directly to `SanitizedOutput`
* Add powerpc64-unknown-linux-musl support
* fix: add copy_file_symlink_to_source for self-installation
* fix: preserve symlinks in copy_dir instead of following them
* feat(cli/rustup-mode): add `doc --rustc-docs` to open rustdoc for Rust internals
* Remove the mixed singular/plural phrasing as "component(s)" instead, use "components" or "component".
In the singular case also add the name of the component for more consistent messaging style with
other info! outputs about single components.
* fix(cli/rustup-mode): `check` for self updates for `SelfUpdateMode::CheckOnly`
* test: Add test for sequential multi-toolchain uninstall
* fix: directory removal race condition in toolchain uninstall
* test(cli_v2): test error when missing many components on install
* fix(dist): adjust printed newlines in `components_missing_msg()`
* unified nightly disclaimer wording/styling; preserved distinct messages per scenario
* Upgrade to reqwest 0.13
* change test name to match new terminology
* rename file to match new terminology
* change 'target triple' to 'target tuple'
* fix(toolchain): forbid toolchain names starting with +
* cli: add `doc --releases` to open release notes
* chore(deps): update actions/upload-artifact action to v6
* chore(deps): update actions/cache action to v5
* dist: use more concise API in helper function
* dist: inline more logic into helper function
* dist: give helper function a more meaningful name
* dist: move helper function closer to usage site
* docs(dev-guide): mention snapshot updating in release process
* fix(toolchain): avoid unwrapping when parsing a toolchain name
* fix(toolchain): change regex to reject leading zeros in toolchain name
* docs(changelog): update for v1.29.0 beta release
* dist: bump `rustup` version to v1.29.0
* docs(changelog): add missing link references
* test(static-roots): use a more compact syntax for raw binaries
* test(static-roots): return `Result` from `store_static_roots()`
* download: statically bundle relevant trust anchors
* Added xonsh support
* refactor(dist/manifestation): remove redundant redeclarations
* docs(dist/download): remove outdated note on concurrent download progress reporting
* fix(dist/download): align `total_bytes` fields in progress reporting UI
* fix: default to GNU host in Cygwin/MSYS/MinGW environments (#4221)
* chore(config): remove redundant imports
* fix(dist/manifestation): print "downloading component" only on `InstallEvents`
* fix(utils): downgrade panic to warning in `delete_dir_contents_following_links()`
* chore(deps): update actions/checkout action to v6
* Prepare for mdbook 0.5 migration
* dist: make installation asynchronous
* dist: make installations 'static
* dist: take ownership of Manifestation
* dist: store owned temp::Context in Transaction
* dist: store temp::Context in DownloadCfg
* dist: align progress bar elements
* dist: track progress during unpacking
* utils: drop unused reader tracking
* process: fix refresh rate for progress bars
* process: reduce duplication in ProgressDrawTarget setup
* Yield references from Manifest::short_name()
* Move Component name helpers to Manifest
* dist: simplify ComponentBinary construction
* dist: hoist creation of io_executor some more
* Move unpack_ram() from dist to diskio
* dist: hoist Executor creation up
* dist: inline effective RAM limit calculation
* dist: hoist environment variable extraction
* dist: use logging for missing parent warnings
* dist: clarify dependency on unpack RAM budget
* diskio: clarify dependency on I/O thread count
* dist: transfer ownership of component values
* dist: take ownership of existing Components
* dist: take ownership of toolchain name in update()
* dist: take ownership of manifest in update()
* dist: derive trivial initialization for Update
* dist: rename Update::build_update() to new()
* dist: linearize for-loop in Update::build_update()
* dist: inline single-use function
* dist: inline trivial helper function
* dist: inline single-use tranaction change helpers
* dist: store specific config bit in Transaction
* chore(config): migrate config .github/renovate.json
* dist: attach manifest download functions to DownloadCfg
* rustup: unhide top-level install/uninstall commands
* dist: move update_from_dist() to DistOptions::install_into()
* Be more consistent about aliases for different subcommands
* test: add test for `rustup toolchain install --no-update`
* feat(rustup-mode): add `no_update` flag to `rustup toolchain install`
* cli: prepare DistOptions in advance
* dist: inline trivial wrapper function
* cli: inline single-use update_all_channels() helper
* config: simplify update_all_channels()
* dist: deduplicate DistOptions initialization
* dist: avoid recomputing dist root URL
* dist: simplify tracing instrumentation
* install: take ownership in InstallMethod::install()
* dist: move DistributableToolchain::install() up
* dist: clarify when update_hash is available
* cli: avoid dropped temporary
* Take semver-compatible dependencies
* dist: install while downloading
* dist: store more context in ComponentBinary
* dist: yield self when download is complete
* dist: move URL alteration logic into DownloadCfg method
* Apply suggestions from clippy 1.91
* refactor(check): Consolidate use_colors checks
* fix(check): Use Cargo's colors
* refactor(check): Make calls more consistent
* dist: drop another layer of abstraction
* dist: store package directory once
* dist: inline short single-use function
* dist: discard unnecessary abstraction layer
* chore(deps): update actions/upload-artifact action to v5
* fix(cli/rustup-mode): add missing self-update in `rustup toolchain install`
* refactor(cli/self-update): move `self_update()` to `SelfUpdateMode::update()`
* refactor(cli/rustup-mode): pass self-update predicates into `self_update()`
* refactor(cli/self-update): import `utils::ExitCode`
* rustup: tweak update check output style
* fix(list): Match show command's styling
* test(list): Add UI test
* fix(toolchain): Have 'list' match 'show's styling
* refactor(toolchain): Order logic by display order
* refactor(toolchain): Use string interpolation
* test(toolchain): Show list's behavior
* fix(update): Match 'cargo update's colors
* refactor(update): Centralize style knowledge
* test: Cover different show_channel_update cases
* fix(check): Subject check to RUSTUP_TERM_COLOR
* test(check): Show current style
* fix: Use HEADER styling in 'rustup show'
* chore: Update clap-cargo
* test: Demonstrate show's behavior
* test(process): Allow forcing color on
* test(process): Ensure non-locked writes are stripped of ANSI escape codes
* cli: update `uninstall_removes_source_from_rcs` to mirror `uninstall_doesnt_modify_rcs_with_no_modify_path`
* cli: add tests for `rustup self uninstall --no-modify-path`
* cli: add `rustup self uninstall --no-modify-path`
* cli: add help text for `rustup self uninstall -y`
* fix(cli/help): change indentation of discussions to 2 spaces
* fix(cli/help): adjust help text for `rustup install`
* feat(cli/help): add toolchain install tips to `rustup update`'s discussion
* feat(cli/help): discuss `rustup toolchain install`
* style: Remove wildcard imports
* progress: modify progress bar's states to be column-aligned
* installations: handle installation of components through progress bars
* feat(cli): Add a sub-heading style for 'completion' Help Discussion
* feat(cli): Have Help Discussions match rest of CLI Help
* feat(cli): Add color to clap help/errors
* refactor(cli): Switch help text to functions
* cli: propagate ActiveSource from the top
* cli: upgrade error events to ERROR level
* cli: inline Cfg::active_rustc_version()
* cli: extract display_version() from rustup main()
* cli: inline Cfg::resolve_local_toolchain()
* cli: inline Cfg::resolve_toolchain()
* config: extract setting of toolchain override in rustup help mode
* cli: avoid Cfg construction indirection
* config: privatize some Cfg fields
* config: drop trivial Cfg setters
* Expand `RUSTUP_TOOLCHAIN_SOURCE`'s documentation
* refactor(installation): extract installation of a component into a separate function
* bin: clean up imports
* cli: rename CLIError to CliError
* config: rename OverrideDB to OverrideDb
* dist: clean up unnecessary qualification
* test: Replace trycmd with snapbox
* chore: Update snapbox
* Update the default Windows SDK version
* refactor(log): Single source RUSTUP_TERM_COLOR
* style: Encourage using existing imports
* process: avoid fine-grained locking for logs
* process: discard unnecessary layer of synchronization
* process: inline TerminalInnerLocked
* process: replace unsafe code with safe equivalent
* process: extract color_choice() method
* process: extract is_a_tty value
* process: inline StreamSelector::is_a_tty()
* process: inline TestWriterLock
* Implement `RUSTUP_TOOLCHAIN_SOURCE` with new `Display` impl
* Move `Display` impl to `to_reason()`
* Rename `ActiveReason` to `ActiveSource`
* dist: simplify DownloadStatus setup
* dist: decentralize download status
* dist: postpone creation of ComponentBinary values
* dist: extract DownloadStatus type
* dist: call DownloadTracker methods directly
* dist: drop unnecessary Notifier layer
* dist: replace PackageContext with DownloadCfg
* refactor: Directly apply styling
* refactor: Don't bother grabbing lock for tests
* refactor: Replace termcolor with anstream
* refactor: Move style building out of ColorableTerminal
* refactor: Migrate to anstyle for color definitions
* fix(www): removes www subdomain from all rust-lang.org urls
* dist: move Notification into dist::download
* notifications: remove unused Display impl
* dist: move Notifier into DownloadCfg
* cli: build Cfg earlier in setup mode
* dist: reuse existing DownloadCfg in update_v1()
* dist: move dist_root out of DownloadCfg
* dist: drop unused Clone derives
* dist: drop Copy derive from DownloadCfg
* dist: move Notifier and DownloadTracker into dist::download
* dist: inline DownloadCfg test setup
* download: move File items down
* download: extract DownloadCfg initialization from Cfg
* config: discard pointless method argument
* cli: rename DownloadTracker::new_with_display_progress() to new()
* notifications: log directly from DownloadTracker
* notifications: log directly on bad download checksums
* notifications: log directly when reusing downloaded files
* notifications: log directly on buffer size changes
* Update platforms to 3.7.0
* notifications: log directly on duplicate toolchain files
* notifications: log directly on metadata upgrades that remove toolchains
* notifications: log directly when reading metadata version
* notifications: log directly when metadata upgrade is not needed
* notifications: log directly when upgrading metadata version
* notifications: log directly when uninstalling toolchains
* notifications: log directly when toolchain is up to date
* notifications: log directly when toolchain has been installed
* notifications: log directly when installing toolchains
* notifications: log the toolchain directory directly
* notifications: log directly when using existing toolchains
* notifications: log directly when looking for toolchains
* notifications: log directly when setting auto-self-update mode
* notifications: log directly when setting profile
* notifications: log directly when setting overrides
* notifications: use human-friendly log format for temp file deletions
* notifications: use human-friendly log format for directory deletions
* notifications: use human-friendly log format for retrying renames
* notifications: use human-friendly log format for path canonicalization
* cli: drop unnecessary generics
* process: import instead of qualifying ColorableTerminal
* process: hide internal structure
* process: don't re-export external items
* process: rename terminalsource to terminal_source
* process: rename filesource to file_source
* process: re-order items in terminalsource module
* feat(cli/self-update): add support for PowerShell on Unix systems
* refactor: Remove unused traits
* refactor: Directly use ColorableTerminal
* refactor: Simplify working with ColorableTerminal
* fix(process): Ensure stdout/stderr lock is held across calls
* refactor(process): Centralize Write bookkeeping
* docs(changelog): describe default profile change during auto-install
* Fix typo in clitools.rs comment
* ci(docs): fix local doc branch name
* Move the default branch from `master` to `main`
* Upgrade opentelemetry dependencies
* ci: use macOS Intel runners
* notifications: log directly when setting the default toolchain
* notifications: log directly when setting auto install mode
* notifications: log directly when resuming partial downloads
* notifications: log directly when downloading files
* notifications: log directly when removing stray hash files
* notifications: log directly when skipping components
* notifications: log directly on missing components
* notifications: log directly when downloading legacy manifests
* notifications: log directly for downloaded manifests
* notifications: log directly for manifest downloads
* notifications: log directly when removing components
* notifications: log directly when installing components
* notifications: log directly after failing to determine memory limit
* notifications: log directly when hash file not found
* notifications: log directly when failing to update hash file
* notifications: log directly when component is already installed
* notifications: log directly for valid checksums
* notifications: log directly when using download backends
* chore: avoid trailing whitespace in error message
* refactor: Switch logging to anstyle
* refactor: Remove unused ColorableTerminal::carriage_return
* notifications: privatize Notification type
* notifications: log directly on creating temp files
* notifications: log directly on temp root creation
* notifications: log directly on file deletions
* notifications: log directly on directory deletions
* notifications: log directly about non-fatal errors
* notifications: log directly about rolling back changes
* notifications: log directly for retrying renames
* notifications: log directly when removing directories
* notifications: log directly when copying directories
* notifications: log directly when linking directories
* notifications: log directly when path canonicalization fails
* notifications: log directly when creating directories
* tests: use DistContext for dist::components tests
* tests: move DistContext into library
* tests: deduplicate distribution installation tests
* notifications: tweak style
* Inline utils Notification variants into top-level Notification
* Inline dist Notification variants into top-level Notification
* Inline dist::temp::Notification variants into top-level Notification
* dist: remove temp::Notification variant from dist::Notification
* dist: extract URL alteration from download() method
* dist: detach download_component() from Manifestation
* dist: introduce ComponentBinary type
* dist: avoid passing through arguments
* dist: avoid unnecessary type annotations
* dist: avoid cloning components Vec
* refactor: remove redundant references
* dist: simpify casting to trait object
* dist: deduplicate decompression setup code
* cli: move more self update logic into self_update module
* refactor(dist/manifestation): remove redundant `.to_string()`
* Remove unneeded paranthesees
* Fix link in the bug reporting template
* ci(all-features/windows): update `OPENSSL_LIB_DIR` for OpenSSL v3 compatibility
* docs(dev-guide): improve suggestion for overriding arg0
* docs(dev-guide): mention the arg0 override trick on welcome page
* docs(README): link CI status badge to GitHub Actions panel
* feat(dist/manifestation): adjust default concurrent downloads when installing toolchains
* feat(cli/rustup-mode): check updates for all channels unless `RUSTUP_CONCURRENT_DOWNLOADS` is set to 1
* refactor: rename `num_channels` to `concurrent_downloads`
* fix: fix hang by preventing `stream.buffered(0)` in concurrent downloads
* test(dist/manifestation): extract `TestContext::*with_env()`
* refactor(download): use `NonZero` instead of `NonZeroU64`
* refactor(process): remove redundant `.context()` in `Process::concurrent_downloads()`
* chore(deps/renovate): group version bumps for `windows-rs` crates
* Upgrade windows crates
* fix(cli/rustup_mode): use ASCII-compatible spinner
* chore(deps): update aws-actions/configure-aws-credentials action to v5
* feat(install): warn if default linker (cc) is missing; add respective test case
* Remove hardcoded dependency to the master branch
* feat(downloads): delay the reappearance of the progress bar when retrying a download
* fix(downloads): correct faulty behavior when a download fails
* fix(downloads): correct faulty output when retrying a download
* feat(self_update): add tcsh shell support to cli #3413
* Replace non_empty_env_var() with Process::var_opt()
* fix(downloads): report real elapsed time of a component downloads instead of cumulative
* Treat empty environment variables as unset
* fix(downloads): honor the RUSTUP_CONCURRENT_DOWNLOADS by always having "n" concurrent downloads
* chore(deps): disable default features for zstd
* feat(downloads): introduce `RUSTUP_CONCURRENT_DOWNLOADS` to control concurrency
* ci(check): make installation of `taplo-cli` faster
* fix(notifications): delete unnecessary Download(Pop/Push)Unit notifications
* fix(downloads): extract closure for downloading a component into a separate function
* feat(downloads): concurrently download components
* fix(downloads): add a comment to justify the unwrap on `.get()` of `OnceLock`
* chore(deps): update actions/checkout action to v5
* fix(download_timeout): introduce RUSTUP_DOWNLOAD_TIMEOUT for overriding download timeout
* fix(downloads): substitute the LazyLock for a OnceLock
* feat(rustup_mode): revise help message
* feat: improve error message for `rustup which`
* test: detach snapshots from component installation order
* feat(download_tracker): refactor in favor of `indicatif`
* feat(process): create a `ProgressDrawTarget` (for `indicatif`) inside the `Process`
* fix(rustup-init/sh): avoid `hw.optional.*: 1` stdout in macOS arch check
* hack(cli/common): suppress host emulation warnings in rustup's own CI
* fix(test/clitools): pass `RUSTUP_CI` to in-process tests
* ci(macos): run x64 workflows with Rosetta 2
* docs(user-guide/environment-variables): clarify the unit of `RUSTUP_UNPACK_RAM`
* docs(user-guide/environment-variables): unify description style
* docs(user-guide/environment-variables): update description of `RUSTUP_IO_THREADS`
* Limit Tokio worker threads to I/O thread count
* Use manual Tokio runtime setup
* Attach io_thread_count() to Process
* Always consider RUSTUP_IO_THREADS as input for thread count
* utils: express io_thread_count() in a simpler way
* opt(err): show renaming file error source
* Set a maximum thread limit for remove_dir_all
* fix(toolchain/distributable): refine handling of known targets with no prebuilt artifacts
* fix(ci/fetch-rust-docker): update comments
* fix(ci/docker): update `CC` name for `powerpc64le-unknown-linux-gnu`
* Extract self_update() from update_all_channels()
* Show channel updates even if self update is not permitted
* Remove Cargo feature indirection
* Move Cfg::get_self_update_mode() to SelfUpdateMode::from_cfg()
* Replace trivial enum with bool
* feat(updates): introduce `RUSTUP_TERM_WIDTH` to override terminal width
* feat(updates): introduce `RUSTUP_TERM_PROGRESS_WHEN` to toggle the progress bars
* Limit the default number of I/O threads
* Bump `toml` to 0.9
* feat(updates): check for updates concurrently
* feat(terminal): implement the `TermLike` trait for `ColorableTerminal`
* chore: use match ergonomics in favor of explicit `ref`s
* refactor(download/curl): use early returns in `download()`
* chore(cli/rustup_mode): merge `std` imports
* chore(cli/rustup-mode): import `std::io`
* chore: fix new `clippy` warnings
* fix(ci/run): specify target triple for `bindgen-cli` installation
* feat(www): improve "copy" button style compatibility with Chromium
* ci(run): install `codegen-cli` with `cargo-binstall`
* docs: replace Discord links
* Block broken snap curl
* Upgrade to windows-sys 0.60
* Emphasize that `llvm-tools` dist component is not subject to compiler stability guarantees
* docs(README): update CI status badge
* Fix rustup-init.sh cputype check for sparcv9
* add Solaris support
* test(clitools)!: remove all deprecated `.expect_*()` APIs
* test(clitools)!: privatize `Config::run()`
* test: migrate remaining uses of `.run()` to `.expect()` APIs
* test(clitools): extract `Assert::redact()`
* test: simplify `.display().to_string()` in `.extend_redactions()`
* test(cli_misc): bring back missing assertions
* Update help.rs: bash completions instructions (#1)
* docs(user-guide): fix typo
* docs(dev-guide): update the section on `clippy` lints
* docs(dev-guide): mention test helpers and `Assert`
* docs(test/clitools): add docs for `Assert`
* Upgrade to rustls-platform-verifier 0.6
* test(cli-v2): migrate to `.expect()` APIs
* test(cli-misc): migrate to `.expect()` APIs
* fix(toolchain): fix proxy fallback notification format on Windows
* test(cli-v1): migrate to `.expect()` APIs
* test(download): serialize tests with proxy-sensitive URLs
* test(cli-rustup): migrate to `.expect()` APIs
* test(clitool): add `Assert::remove_redactions()`
* test(clitools): allow `OsStr`-like args in `Config::expect*()`
* Fix CI image names for downloading ARM and PowerPC artifacts
* Update platforms to 3.6
* test(cli-exact): migrate to `.expect()` APIs
* Avoid swallowing errors in show()
* Simplify target processing logic
* Inline returned bindings
* Increase Windows main thread stack size to 2mb
* test(cli-inst-interactive): migrate to `.expect()` APIs
* Unset RUSTUP_AUTO_INSTALL for tests
* test(cli-paths): migrate to `.expect()` APIs
* test(cli-exact): use the new `[CURRENT_VERSION]` redaction
* test(cli-self-upd): migrate to `.expect()` APIs
* Tweak list_items() docstring
* Leverage bool::then_some() to simplify some code
* Avoid intermediate allocation in listing
* test(custom-toolchains): `target list` now can display the installed targets
* feat(custom-toolchains): `target` and `component list` working on custom toolchains
* Skip manifest loading if there are no components/targets to check
* fix(deps): update rust crate opener to 0.8.0
* rustup check: set exit status based on available updates
* rustup check: adopt no-self-update logic
* feat(self_update): add proxy sanity checks
* style(test): qualify uses of `snapbox::str![]`
* refactor(test): migrate some tests to `.expect()` APIs
* chore(test): deprecated old APIs overlapping with the new ones
* refactor(test): add new `.expect()`-based testing APIs
* test(custom-toolchains): using `show` on a custom toolchain without a `components` file
* test(custom-toolchains): add test to showcase that the issue was solved
* feat(custom-toolchains): `rustup show` now reporting installed targets
* tests: print diffs on test failures
* Log versions during self updates
* Fix cargo lints on Windows
* toolchain: hoist binary name conditionals out of fallback functions
* refactor(test): replace `TempDir::into_path()` with `TempDir::keep()`
* refactor(test/clitools): use globally-defined `tempdir_in_with_prefix()`
* feat(toolchain): notify the user when proxy fallback is activated
* feat(toolchain): consider external `rust-analyzer` when calling a proxy
* refactor(toolchain): move predicates into `Toolchain::maybe_do_cargo_fallback()`
* refactor(toolchain): privatize `Toolchain::maybe_do_cargo_fallback()`
* deps: update aws-lc-rs to 1.13.1
* docs(changelog): mirror changes from the release announcement, take 2
* Deprecate native-tls as well
* Enable HTTP/2 support for reqwest download backend
* Emit tracing events from log facade calls
* download: show Debug representation for errors
* Avoid repeated globals in tracing events
* Log original download errors immediately
* feat(cli/rustup-mode): add aliases to `rustup component remove`
* Switch flate2 to use the zlib-rs backend
* Hardlink proxies if symlinks aren't reachable
* Add powerpc64le-unknown-linux-musl support
* Add toolchain_name to not installed bail msg
* Warn about using curl
* Drop workspace indirection
* Fold download crate back into rustup
* download: merge integration test files
* Test CARGO environment replacement
* Update CARGO env var if it is a rustup proxy
* Tweak toolchain subcommand help text
* Move toolchain and default commands first
* show toolchain paths in rustup show -v output
* refactor(cli/self-update): save allocations in `Nu::rcfiles()`
* fix(cli/self-update)!: stop appending to `env.nu` due to deprecation
* fix(cli/self-update): consider Windows paths in Nushell suggestions
* refactor(cli/self-update): use `path add` in `env.nu` template
* fix(cli/self-update): use interpolated string in `env.nu` template
* Upgrade dependencies
* docs(user-guide/environment-variables): document `RUSTUP_VERSION`
* feat(rustup-init/sh): allow setting `RUSTUP_VERSION` during installation
* feat(cli/self-update): allow setting `RUSTUP_VERSION` for arbitrary
downgrades
* feat(test/clitools): add `Config::expect_ok_ex_env()`
* fix(errors)!: improve error messages for `RustupError::ToolchainNotInstalled`
* Add set auto-install disable
* Use `cursor: pointer` for copy button on website
* fix(dist): refine suggestions about missing targets
* Append Windows bin directory to PATH by default
* Remove validation for custom toolchains when reading rust-toolchain.toml
* document RUSTUP_AUTO_INSTALL
* Fix build script `cargo` instructions
Patchnames: openSUSE-Leap-16.0-1824
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
4.2 (Medium)
Affected products
Recommended
2 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64 | — |
Vendor Fix
|
Threats
Impact
moderate
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
low
7.5 (High)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
important
7.5 (High)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
important
6.5 (Medium)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
moderate
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
moderate
7.4 (High)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
important
5.9 (Medium)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
moderate
6.5 (Medium)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
moderate
7.5 (High)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
important
4.8 (Medium)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
moderate
6.5 (Medium)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
moderate
7.5 (High)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
important
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
important
4.4 (Medium)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
important
5.9 (Medium)
Affected products
Recommended
2 products, the same list as for
CVE-2024-12224
Threats
Impact
important
References
71 references
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "important"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "Security update for rustup",
"title": "Title of the patch"
},
{
"category": "description",
"text": "This update for rustup fixes the following issues:\n\n- CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243862).\n- CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249008).\n- CVE-2026-25541: bytes: integer overflow in \u0027BytesMut:reserve\u0027 can lead to undefined behavior and crashes\n (bsc#1274144).\n- CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion\n (bsc#1257902).\n- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1\n (bsc#1270186).\n- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-\n openssl crate (bsc#1270619).\n- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270644).\n- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate\n (bsc#1270795).\n- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent\n memory in rust-openssl crate (bsc#1270870).\n- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate\n (bsc#1270521).\n- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate\n (bsc#1270874).\n- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-\n openssl crate (bsc#1270989).\n- CVE-2026-93599: rustls-webpki: panic via empty BIT STRING (bsc#1282217).\n- CVE-2026-93600: rustls-webpki: name constraints URI validation bypass (bsc#1282217).\n- CVE-2026-93601: rustls-webpki: name constraint bypass (bsc#1282217).\n- CVE-2026-93602: rustls-webpki: CRL revocation check bypass (bsc#1282217).\n- rust-shlex: Multiple issues involving quote API (RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032).\n\nChanges for rustup:\n\n- Update to version 1.29.1~0:\n * dist(rustup-init/sh): update commit shasum in help string\n * style(bin/rustup-init): reformat code\n * docs(changelog): update for v1.29.1 stable release\n * warn how to switch away from the deprecated complete profile\n * fix(cli/help): fix wording in `rustup run --help`\n * ci(docker/android): stop building OpenSSL\n * refactor(cli/docs): use tracing for docs opening status messages\n * refactor(self-update): rename Windows uninstall registry helpers\n * feat(test): isolate Windows registry state per test\n * docs(dev-guide): mention how to support new compilation targets\n * Fix funding link\n * chore(deps): lock file maintenance\n * refactor(cli/self-update): move `current_install_opts()` to `InstallOpts::display()`\n * refactor(cli/self-update): move `process` out of `InstallOpts`\n * fix(cli/self-update): postpone initialization of `Cfg` in `setup_mode`\n * refactor(cli/self-update): take `Process` in `check_existence_of_settings_file()`\n * fix(settings): prevent creating new file with `SettingsFile::read_settings()`\n * test(cli-inst-interactive): test file creation on cancelled installation\n * refactor(toolchain/names): inline `validate()` aliases into `FromStr`\n * refactor(toolchain/names): rename `validate()` to `normalize_name()`\n * fix minor typos\n * www: align copy icon\n * refactor(toolchain/names)!: remove `try_from_str!()`\n * refactor(toolchain/names)!: remove `from_variant!()`\n * Add `rustup doc --serve` to serve docs over local HTTP\n * Move doc() and man() into a new docs module\n * chore(github): comment out instructions in PR template\n * docs(dev-guide): reapply abandoned changes from #4970\n * Add riscv64 unknown linux musl support\n * fix(deps): update rust crate enum-map to v3\n * refactor(cli/self-update)!: rename `install()` to `InstallOpts::install()`\n * refactor(cli/self-update)!: rename `maybe_install_rust()` to `InstallOpts::install_rust()`\n * refactor(cli/self-update)!: rename `InstallOpts::install()` to `InstallOpts::select_toolchain()`\n * refactor(toolchain/names)!: make more clones during conversions explicit\n * refactor(cli/self-update): move message templates to `mod msg`\n * style(cli/self-update): reorganize imports\n * Add pull request template linking to the dev guide\n * doc: add AI policy to the dev guide\n * ci(dist): ensure pushing to `dev-static` on `stable` update\n * test(toolchain): add a test case for `rustup toolchain install --override`\n * feat(toolchain): add `--default` flag to `rustup toolchain install`\n * fix(toolchain): inline use of `set_override`\n * Add Enzyme to the list of rustup components\n * fix: repair toolchains without an installed manifest\n * refactor: expose the installed manifest path\n * Docs: Remove i686 `set default-host` example\n * fix(self-update): only remove complete profile lines\n * chore(deps): bump `platforms` to 4.1.0\n * chore(deps): remove pinned `openssl-src`\n * refactor: replace `cfg_if!{}` with `cfg_select!{}`\n * fix: Lock state file updates\n * Fix Rust 1.97 clippy warnings\n * uninstalls toolchains prior to deleting the rustup home folder\n * Take semver-compatible dependency updates\n * Upgrade platforms to 4\n * docs: update `CHANGELOG` for v1.29.1\n * Lock file maintenance\n * Remove Windows special case from `can_run`\n * diskio: drop unnecessary constructor wrapper\n * diskio: rename _IncrementalFileState to FileState\n * diskio: inline IncrementalFileState type alias\n * Minimize API visibility\n * toolchain: streamline validate() implementations\n * toolchain: avoid internal cloning\n * dist: drop unused conversion impl\n * dist: keep impls with type definitions\n * Don\u0027t hide allocations inside From impls\n * toolchain: drop impls for \u0026String\n * Warn on clippy::or_fun_call\n * Warn on clippy::needless_by_ref_mut\n * Warn on clippy::redundant_clone\n * Warn on clippy::manual_let_else\n * Warn on clippy::use_self\n * errors: box ToolchainDesc in RustupError variants\n * errors: box Manifest in RequestedComponentsUnavailable variant\n * No (more) need to allow clippy::arc_with_non_send_sync\n * Replace use of FnMut trait objects with custom trait\n * test(cli/self-upd): use direct arg0 override for `as_rustup_setup()`\n * chore(deps): update actions/cache action to v6\n * ci(windows): add support for aarch64-pc-windows-gnullvm target\n * ci(windows): refine MSVC/MINGW job step predicates\n * chore(deps): update actions/checkout action to v7\n * fix(deps): update rust crate itertools to 0.15\n * fix(progress): use the `prefix` placeholder instead of `msg` for component name\n * rustup: warn when no toolchain or default is configured\n * errors: extract default stable hint\n * feat(toolchain): make the \"installed\" text of a toolchain install green\n * Add aarch64-unknown-freebsd\n * chore: address linter warnings\n * chore(deps): bump to semver-compatible versions\n * Add funding links\n * ci(docker/freebsd): bump `clang` version to `freebsd14`\n * ci(freebsd): use FreeBSD 14.0 for full CI\n * chore(deps): update `curl`\n * feat(cli/rustup-mode): warn about auto-installation in some subcommands\n * refactor(config): accept `Cfg` in `EnsureInstalled::warn_auto_install()`\n * test(cli/rustup-mode): test auto-installation on to-be-deprecated subcommand\n * dist: move display_name() before other methods that it calls\n * chore(gitignore): add .cargo/config.windows-cross.toml to gitignore\n * docs(dev-guide): update platform-specific code guidance\n * docs(dev-guide): mention rust-analyzer support for Windows-specific code on Unix\n * docs(dev-guide): mention how to lint Windows-specific code on Unix\n * chore(config): add example config for cross checking and rust-analyzer\n * chore: add rust-analyzer example config\n * Display the full names of targets not matching the host target tuple\n * docs(dev-guide/tips-and-tricks): mention the `RUSTUP_FORCE_ARG0=\u0027rustup\u0027` cargo alias\n * build(cargo): add `cargo` alias for `RUSTUP_FORCE_ARG0=\u0027rustup\u0027`\n * docs: rename the repath helper variable\n * Remove double buffering when extracting archives\n * refactor(toolchain/distributable): return `EnsureInstalled\u003c\u003e` from `DistributableToolchain::install()`\n * docs(dev-guide/coding-standards): adapt style guide from rustls\n * fix(deps): update opentelemetry\n * feat(config): warn user if auto-install is enabled\n * refactor(config): return `EnsureInstalled\u003c\u003e` from more functions\n * refactor(config): extract `EnsureInstalled\u003c\u003e` wrapper type\n * test: make tests agnostic to external `RUSTUP_AUTO_INSTALL` and `RUST_RECURSION_COUNT`\n * test(dist): fail v2 manifest update when manifest disagrees with .sha256\n * fix(dist): propagate v2 manifest checksum failure instead of reporting \"unchanged\"\n * Align shell setup comments in install message\n * feat(cli/self-update): refine wording of \"already installed Rust\" warning\n * chore(settings): rename default_host_triple to default_host_tuple and alias old name\n * chore(settings): add test to parse default_host_triple in toml\n * test(download): also scrub `HTTP_PROXY` in `scrub_env()`\n * chore: document legacy default host setting\n * chore: rename internal tuple constants\n * chore: rename partially \"Triple\" to \"Tuple\" to reflect the new terminology\n * fix(cli/rustup-mode)!: complete `rustup show` if active toolchain is not installed\n * refactor(cli/rustup-mode): postpone eval of `active_toolchain_targets` in `show()`\n * refactor(cli/rustup-mode): postpone eval of `active_toolchain` in `show()`\n * refactor(cli/rustup-mode): reduce rightward drift in `show()`\n * refactor(cli/rustup-mode): refine usage of `stdout` term and locks in `show()`\n * feat(config): add `Cfg` field to force-disable auto-installation\n * Provide --yes alias for -y flag consistently\n * refactor(tests): rename triple to tuple\n * refactor: bulk rename triple to ruple\n * refactor: rename get_default_host_triple to default_host_tuple\n * test(download): support more feature flag combinations\n * docs: fix the FileBuffer::clear doc comment wording\n * docs: fix plural of VM in coding standards\n * fix(dist): bulk rename triple to tuple for variables and messages\n * refactor(dist): rename PartialTargetTriple to PartialTargetTuple\n * refactor(dist): rename triple module to target_tuple\n * refactor: remove PartialToochainDesc::has_triple() in favor to PartialTargetTriple::is_empty()\n * refactor(dist): rename TargetTriple to TargetTuple\n * fix(self-update): rename triple to tuple in self_update\n * dist: bump `rustup` version to v1.29.1\n * ci(linux/x64-musl): install missing libc dependencies\n * fix(tests): rename HOST_TRIPLE placeholder to HOST_TUPLE\n * fix(tests): rename this_host_triple() to this_host_tuple()\n * fix(init): rename triple to tuple to reflect the new terminology\n * fix(docs): rename triple to tuple to reflect the new terminology\n * chore(deps): update ubuntu docker tag to v26\n * Improve error message for incomplete toolchains\n * chore(deps): update bwoodsend/setup-winlibs-action action to v1.16\n * test(dist/manifest): use the reordered fixture in `manifest_serialized_with_sorted_keys`\n * docs: fix \"initial\" spelling in stylesheet variable\n * ci: powerpc64-unknown-linux-musl is now stable\n * style(cli/rustup-mode): address clippy warnings\n * docs(dev-guide): update release process with new backporting flow\n * docs: fix actions template README typo\n * Only show post-install instructions for currently installed shells\n * docs: fix Windows MSVC guide typo\n * Upgrade to rustls-platform-verifier 0.7\n * Make component removal best-effort and preserve single-error behavior\n * Use `cc-rs` to detect the default linker, instead of assuming `cc`\n * ci(test): add `workflow_dispatch` trigger on par with `schedule`\n * ci: fix incorrect `contains()` predicate\n * fix(dist/manifestation): fix log format when installing exactly 2 components\n * Allow rustup component add to install multiple components in one update #4787\n * fix(docs): correct link to `no-self-update` feature\n * ci: enable on all PR target branches\n * ci(backport): rename backport branches to `release/*`\n * feat(toolchain): run a pre-check before updating all toolchains\n * feat(install): accept an optional pre-fetched manifest when installing\n * fix(toolchain): extract manifest fetching out of `show_dist_version()`\n * fix(manifest): aggregate a manifest and its hash in a `ManifestWithHash` struct\n * fix: Reduce flickering by using `set_move_cursor`\n * ci(backport): add support for backporting\n * fix: install message misalignment.\n * refactor: extracted `progress_style` method for DownloadStatus\n * fix(deps): update rust crate sha2 to 0.11\n * chore(doc): Added comments for clarify the usage of `Component::name` `Manifest::name` and the `short_name` funcc accordingly.\n * refactor: Rename `Component`\u0027s `name_in_manifest` to `name` and `short_name` accordingly\n * self_update: show path to executable in case of updater failure\n * Revert \"fix(ci/freebsd): install ca certs to prevent certificate-related issues\"\n * ci: don\u0027t install protoc\n * Update to mdbook 0.5\n * ci(all-features): bump protoc version\n * fix(dist/manifestation): use full toolchain name in `Update::unavailable_components()`\n * style(dist/manifestation): merge imports\n * Fix zsh completion showing all PATH entries for +toolchain arg\n * fix(cli/proxy-mode): stop enforcing `quiet: true`\n * chore(deps/freebsd): downgrade `libz-sys` to v1.1.24\n * fix(ci/freebsd): install ca certs to prevent certificate-related issues\n * fix(rustup-init/sh): prevent passing `--default-host` twice\n * Avoid warning about the existence of a `settings.toml` on a fresh install\n * use tuple instead of triple for env overrides\n * Take platforms 3.9.0\n * Unpin tracing-subcriber\n * chore(deps): update `aws-lc-rs` and `aws-lc-sys`\n * docs(changelog): update release date for v1.29.0\n * docs(dev-guide/release-process): mention the CfT blog post\n * docs(changelog): update for v1.29.0 stable release\n * fix(cli): Style CLI errors in init mode\n * test: Add unknown arg init test\n * chore(deps): update actions/upload-artifact action to v7\n * refactor(www): simplify instruction css selector\n * feat(www): make copy button dark mode-aware\n * feat(www): move feedback text out of copy button\n * fix(www): apply filter to rust logo\n * feat(www): add dark mode\n * refactor(www): extract css variables\n * fix(cli/self-update): enforce a newline after `check_updates()`\n * refactor(cli/self-update): extract `has_progress_bars` in `check_updates()`\n * fix(cli/self-update): unify `check_*update*()`\u0027s message formats\n * docs(downloads): fix the default number of `RUSTUP_CONCURRENT_DOWNLOADS`\n * feat(toolchain): add `--override` to override toolchain as soon as installed\n * fix(toolchain): improve logs when recovering from an interrupted installation\n * chore(deps): downgrade `openssl-src` to 300.5.4+3.5.4\n * style(download): clean up imports\n * fix(diskio): fall back to single-threaded unpacking when `ram_budget` \u003c 512MB to avoid OOM on memory-constrained systems\n * test(downloads): check if an error is thrown if the server does not honor range\n * fix(downloads): check correct response when resuming from partial (reqwest)\n * fix(downloads): check correct response when resuming from partial (curl)\n * fix(deps): update rust crate toml to v1\n * fix(dist/manifest): sort keys when serializing `Manifest`\n * hack(ci/linux): disable BuildKit when building local images\n * chore(ci): use more distinctive local image names\n * Upgrade rand to 0.10\n * Upgrade snapbox to 1\n * Upgrade to anstream 1\n * fix(downloads): adjust error message for partial files in network failures\n * test(downloads): ensure that partial files are not removed when network fails\n * feat(downloads): do not delete partial download when network fails\n * fix(downloads): substitute `DEK` alias for `DownloadError`\n * chore(deps): update aws-actions/configure-aws-credentials action to v6\n * cli: introduce semantic exit code constants for rustup check\n * Add missing Windows SDK instructions\n * Add winget instructions to MSVC install page\n * Remove nu-string-interpolation `$`\n * Replace $nu.home-path with ~\n * feat(cli/rustup-mode): add \"Exit status\" section to `rustup check --help`\n * Add common commands section in help text\n * fix(cli/rustup-mode): improve exit code of `rustup check`\n * refactor(test)!: pass status code directly to `SanitizedOutput`\n * Add powerpc64-unknown-linux-musl support\n * fix: add copy_file_symlink_to_source for self-installation\n * fix: preserve symlinks in copy_dir instead of following them\n * feat(cli/rustup-mode): add `doc --rustc-docs` to open rustdoc for Rust internals\n * Remove the mixed singular/plural phrasing as \"component(s)\" instead, use \"components\" or \"component\".\n In the singular case also add the name of the component for more consistent messaging style with\n other info! outputs about single components.\n * fix(cli/rustup-mode): `check` for self updates for `SelfUpdateMode::CheckOnly`\n * test: Add test for sequential multi-toolchain uninstall\n * fix: directory removal race condition in toolchain uninstall\n * test(cli_v2): test error when missing many components on install\n * fix(dist): adjust printed newlines in `components_missing_msg()`\n * unified nightly disclaimer wording/styling; preserved distinct messages per scenario\n * Upgrade to reqwest 0.13\n * change test name to match new terminology\n * rename file to match new terminology\n * change \u0027target triple\u0027 to \u0027target tuple\u0027\n * fix(toolchain): forbid toolchain names starting with +\n * cli: add `doc --releases` to open release notes\n * chore(deps): update actions/upload-artifact action to v6\n * chore(deps): update actions/cache action to v5\n * dist: use more concise API in helper function\n * dist: inline more logic into helper function\n * dist: give helper function a more meaningful name\n * dist: move helper function closer to usage site\n * docs(dev-guide): mention snapshot updating in release process\n * fix(toolchain): avoid unwrapping when parsing a toolchain name\n * fix(toolchain): change regex to reject leading zeros in toolchain name\n * docs(changelog): update for v1.29.0 beta release\n * dist: bump `rustup` version to v1.29.0\n * docs(changelog): add missing link references\n * test(static-roots): use a more compact syntax for raw binaries\n * test(static-roots): return `Result` from `store_static_roots()`\n * download: statically bundle relevant trust anchors\n * Added xonsh support\n * refactor(dist/manifestation): remove redundant redeclarations\n * docs(dist/download): remove outdated note on concurrent download progress reporting\n * fix(dist/download): align `total_bytes` fields in progress reporting UI\n * fix: default to GNU host in Cygwin/MSYS/MinGW environments (#4221)\n * chore(config): remove redundant imports\n * fix(dist/manifestation): print \"downloading component\" only on `InstallEvents`\n * fix(utils): downgrade panic to warning in `delete_dir_contents_following_links()`\n * chore(deps): update actions/checkout action to v6\n * Prepare for mdbook 0.5 migration\n * dist: make installation asynchronous\n * dist: make installations \u0027static\n * dist: take ownership of Manifestation\n * dist: store owned temp::Context in Transaction\n * dist: store temp::Context in DownloadCfg\n * dist: align progress bar elements\n * dist: track progress during unpacking\n * utils: drop unused reader tracking\n * process: fix refresh rate for progress bars\n * process: reduce duplication in ProgressDrawTarget setup\n * Yield references from Manifest::short_name()\n * Move Component name helpers to Manifest\n * dist: simplify ComponentBinary construction\n * dist: hoist creation of io_executor some more\n * Move unpack_ram() from dist to diskio\n * dist: hoist Executor creation up\n * dist: inline effective RAM limit calculation\n * dist: hoist environment variable extraction\n * dist: use logging for missing parent warnings\n * dist: clarify dependency on unpack RAM budget\n * diskio: clarify dependency on I/O thread count\n * dist: transfer ownership of component values\n * dist: take ownership of existing Components\n * dist: take ownership of toolchain name in update()\n * dist: take ownership of manifest in update()\n * dist: derive trivial initialization for Update\n * dist: rename Update::build_update() to new()\n * dist: linearize for-loop in Update::build_update()\n * dist: inline single-use function\n * dist: inline trivial helper function\n * dist: inline single-use tranaction change helpers\n * dist: store specific config bit in Transaction\n * chore(config): migrate config .github/renovate.json\n * dist: attach manifest download functions to DownloadCfg\n * rustup: unhide top-level install/uninstall commands\n * dist: move update_from_dist() to DistOptions::install_into()\n * Be more consistent about aliases for different subcommands\n * test: add test for `rustup toolchain install --no-update`\n * feat(rustup-mode): add `no_update` flag to `rustup toolchain install`\n * cli: prepare DistOptions in advance\n * dist: inline trivial wrapper function\n * cli: inline single-use update_all_channels() helper\n * config: simplify update_all_channels()\n * dist: deduplicate DistOptions initialization\n * dist: avoid recomputing dist root URL\n * dist: simplify tracing instrumentation\n * install: take ownership in InstallMethod::install()\n * dist: move DistributableToolchain::install() up\n * dist: clarify when update_hash is available\n * cli: avoid dropped temporary\n * Take semver-compatible dependencies\n * dist: install while downloading\n * dist: store more context in ComponentBinary\n * dist: yield self when download is complete\n * dist: move URL alteration logic into DownloadCfg method\n * Apply suggestions from clippy 1.91\n * refactor(check): Consolidate use_colors checks\n * fix(check): Use Cargo\u0027s colors\n * refactor(check): Make calls more consistent\n * dist: drop another layer of abstraction\n * dist: store package directory once\n * dist: inline short single-use function\n * dist: discard unnecessary abstraction layer\n * chore(deps): update actions/upload-artifact action to v5\n * fix(cli/rustup-mode): add missing self-update in `rustup toolchain install`\n * refactor(cli/self-update): move `self_update()` to `SelfUpdateMode::update()`\n * refactor(cli/rustup-mode): pass self-update predicates into `self_update()`\n * refactor(cli/self-update): import `utils::ExitCode`\n * rustup: tweak update check output style\n * fix(list): Match show command\u0027s styling\n * test(list): Add UI test\n * fix(toolchain): Have \u0027list\u0027 match \u0027show\u0027s styling\n * refactor(toolchain): Order logic by display order\n * refactor(toolchain): Use string interpolation\n * test(toolchain): Show list\u0027s behavior\n * fix(update): Match \u0027cargo update\u0027s colors\n * refactor(update): Centralize style knowledge\n * test: Cover different show_channel_update cases\n * fix(check): Subject check to RUSTUP_TERM_COLOR\n * test(check): Show current style\n * fix: Use HEADER styling in \u0027rustup show\u0027\n * chore: Update clap-cargo\n * test: Demonstrate show\u0027s behavior\n * test(process): Allow forcing color on\n * test(process): Ensure non-locked writes are stripped of ANSI escape codes\n * cli: update `uninstall_removes_source_from_rcs` to mirror `uninstall_doesnt_modify_rcs_with_no_modify_path`\n * cli: add tests for `rustup self uninstall --no-modify-path`\n * cli: add `rustup self uninstall --no-modify-path`\n * cli: add help text for `rustup self uninstall -y`\n * fix(cli/help): change indentation of discussions to 2 spaces\n * fix(cli/help): adjust help text for `rustup install`\n * feat(cli/help): add toolchain install tips to `rustup update`\u0027s discussion\n * feat(cli/help): discuss `rustup toolchain install`\n * style: Remove wildcard imports\n * progress: modify progress bar\u0027s states to be column-aligned\n * installations: handle installation of components through progress bars\n * feat(cli): Add a sub-heading style for \u0027completion\u0027 Help Discussion\n * feat(cli): Have Help Discussions match rest of CLI Help\n * feat(cli): Add color to clap help/errors\n * refactor(cli): Switch help text to functions\n * cli: propagate ActiveSource from the top\n * cli: upgrade error events to ERROR level\n * cli: inline Cfg::active_rustc_version()\n * cli: extract display_version() from rustup main()\n * cli: inline Cfg::resolve_local_toolchain()\n * cli: inline Cfg::resolve_toolchain()\n * config: extract setting of toolchain override in rustup help mode\n * cli: avoid Cfg construction indirection\n * config: privatize some Cfg fields\n * config: drop trivial Cfg setters\n * Expand `RUSTUP_TOOLCHAIN_SOURCE`\u0027s documentation\n * refactor(installation): extract installation of a component into a separate function\n * bin: clean up imports\n * cli: rename CLIError to CliError\n * config: rename OverrideDB to OverrideDb\n * dist: clean up unnecessary qualification\n * test: Replace trycmd with snapbox\n * chore: Update snapbox\n * Update the default Windows SDK version\n * refactor(log): Single source RUSTUP_TERM_COLOR\n * style: Encourage using existing imports\n * process: avoid fine-grained locking for logs\n * process: discard unnecessary layer of synchronization\n * process: inline TerminalInnerLocked\n * process: replace unsafe code with safe equivalent\n * process: extract color_choice() method\n * process: extract is_a_tty value\n * process: inline StreamSelector::is_a_tty()\n * process: inline TestWriterLock\n * Implement `RUSTUP_TOOLCHAIN_SOURCE` with new `Display` impl\n * Move `Display` impl to `to_reason()`\n * Rename `ActiveReason` to `ActiveSource`\n * dist: simplify DownloadStatus setup\n * dist: decentralize download status\n * dist: postpone creation of ComponentBinary values\n * dist: extract DownloadStatus type\n * dist: call DownloadTracker methods directly\n * dist: drop unnecessary Notifier layer\n * dist: replace PackageContext with DownloadCfg\n * refactor: Directly apply styling\n * refactor: Don\u0027t bother grabbing lock for tests\n * refactor: Replace termcolor with anstream\n * refactor: Move style building out of ColorableTerminal\n * refactor: Migrate to anstyle for color definitions\n * fix(www): removes www subdomain from all rust-lang.org urls\n * dist: move Notification into dist::download\n * notifications: remove unused Display impl\n * dist: move Notifier into DownloadCfg\n * cli: build Cfg earlier in setup mode\n * dist: reuse existing DownloadCfg in update_v1()\n * dist: move dist_root out of DownloadCfg\n * dist: drop unused Clone derives\n * dist: drop Copy derive from DownloadCfg\n * dist: move Notifier and DownloadTracker into dist::download\n * dist: inline DownloadCfg test setup\n * download: move File items down\n * download: extract DownloadCfg initialization from Cfg\n * config: discard pointless method argument\n * cli: rename DownloadTracker::new_with_display_progress() to new()\n * notifications: log directly from DownloadTracker\n * notifications: log directly on bad download checksums\n * notifications: log directly when reusing downloaded files\n * notifications: log directly on buffer size changes\n * Update platforms to 3.7.0\n * notifications: log directly on duplicate toolchain files\n * notifications: log directly on metadata upgrades that remove toolchains\n * notifications: log directly when reading metadata version\n * notifications: log directly when metadata upgrade is not needed\n * notifications: log directly when upgrading metadata version\n * notifications: log directly when uninstalling toolchains\n * notifications: log directly when toolchain is up to date\n * notifications: log directly when toolchain has been installed\n * notifications: log directly when installing toolchains\n * notifications: log the toolchain directory directly\n * notifications: log directly when using existing toolchains\n * notifications: log directly when looking for toolchains\n * notifications: log directly when setting auto-self-update mode\n * notifications: log directly when setting profile\n * notifications: log directly when setting overrides\n * notifications: use human-friendly log format for temp file deletions\n * notifications: use human-friendly log format for directory deletions\n * notifications: use human-friendly log format for retrying renames\n * notifications: use human-friendly log format for path canonicalization\n * cli: drop unnecessary generics\n * process: import instead of qualifying ColorableTerminal\n * process: hide internal structure\n * process: don\u0027t re-export external items\n * process: rename terminalsource to terminal_source\n * process: rename filesource to file_source\n * process: re-order items in terminalsource module\n * feat(cli/self-update): add support for PowerShell on Unix systems\n * refactor: Remove unused traits\n * refactor: Directly use ColorableTerminal\n * refactor: Simplify working with ColorableTerminal\n * fix(process): Ensure stdout/stderr lock is held across calls\n * refactor(process): Centralize Write bookkeeping\n * docs(changelog): describe default profile change during auto-install\n * Fix typo in clitools.rs comment\n * ci(docs): fix local doc branch name\n * Move the default branch from `master` to `main`\n * Upgrade opentelemetry dependencies\n * ci: use macOS Intel runners\n * notifications: log directly when setting the default toolchain\n * notifications: log directly when setting auto install mode\n * notifications: log directly when resuming partial downloads\n * notifications: log directly when downloading files\n * notifications: log directly when removing stray hash files\n * notifications: log directly when skipping components\n * notifications: log directly on missing components\n * notifications: log directly when downloading legacy manifests\n * notifications: log directly for downloaded manifests\n * notifications: log directly for manifest downloads\n * notifications: log directly when removing components\n * notifications: log directly when installing components\n * notifications: log directly after failing to determine memory limit\n * notifications: log directly when hash file not found\n * notifications: log directly when failing to update hash file\n * notifications: log directly when component is already installed\n * notifications: log directly for valid checksums\n * notifications: log directly when using download backends\n * chore: avoid trailing whitespace in error message\n * refactor: Switch logging to anstyle\n * refactor: Remove unused ColorableTerminal::carriage_return\n * notifications: privatize Notification type\n * notifications: log directly on creating temp files\n * notifications: log directly on temp root creation\n * notifications: log directly on file deletions\n * notifications: log directly on directory deletions\n * notifications: log directly about non-fatal errors\n * notifications: log directly about rolling back changes\n * notifications: log directly for retrying renames\n * notifications: log directly when removing directories\n * notifications: log directly when copying directories\n * notifications: log directly when linking directories\n * notifications: log directly when path canonicalization fails\n * notifications: log directly when creating directories\n * tests: use DistContext for dist::components tests\n * tests: move DistContext into library\n * tests: deduplicate distribution installation tests\n * notifications: tweak style\n * Inline utils Notification variants into top-level Notification\n * Inline dist Notification variants into top-level Notification\n * Inline dist::temp::Notification variants into top-level Notification\n * dist: remove temp::Notification variant from dist::Notification\n * dist: extract URL alteration from download() method\n * dist: detach download_component() from Manifestation\n * dist: introduce ComponentBinary type\n * dist: avoid passing through arguments\n * dist: avoid unnecessary type annotations\n * dist: avoid cloning components Vec\n * refactor: remove redundant references\n * dist: simpify casting to trait object\n * dist: deduplicate decompression setup code\n * cli: move more self update logic into self_update module\n * refactor(dist/manifestation): remove redundant `.to_string()`\n * Remove unneeded paranthesees\n * Fix link in the bug reporting template\n * ci(all-features/windows): update `OPENSSL_LIB_DIR` for OpenSSL v3 compatibility\n * docs(dev-guide): improve suggestion for overriding arg0\n * docs(dev-guide): mention the arg0 override trick on welcome page\n * docs(README): link CI status badge to GitHub Actions panel\n * feat(dist/manifestation): adjust default concurrent downloads when installing toolchains\n * feat(cli/rustup-mode): check updates for all channels unless `RUSTUP_CONCURRENT_DOWNLOADS` is set to 1\n * refactor: rename `num_channels` to `concurrent_downloads`\n * fix: fix hang by preventing `stream.buffered(0)` in concurrent downloads\n * test(dist/manifestation): extract `TestContext::*with_env()`\n * refactor(download): use `NonZero` instead of `NonZeroU64`\n * refactor(process): remove redundant `.context()` in `Process::concurrent_downloads()`\n * chore(deps/renovate): group version bumps for `windows-rs` crates\n * Upgrade windows crates\n * fix(cli/rustup_mode): use ASCII-compatible spinner\n * chore(deps): update aws-actions/configure-aws-credentials action to v5\n * feat(install): warn if default linker (cc) is missing; add respective test case\n * Remove hardcoded dependency to the master branch\n * feat(downloads): delay the reappearance of the progress bar when retrying a download\n * fix(downloads): correct faulty behavior when a download fails\n * fix(downloads): correct faulty output when retrying a download\n * feat(self_update): add tcsh shell support to cli #3413\n * Replace non_empty_env_var() with Process::var_opt()\n * fix(downloads): report real elapsed time of a component downloads instead of cumulative\n * Treat empty environment variables as unset\n * fix(downloads): honor the RUSTUP_CONCURRENT_DOWNLOADS by always having \"n\" concurrent downloads\n * chore(deps): disable default features for zstd\n * feat(downloads): introduce `RUSTUP_CONCURRENT_DOWNLOADS` to control concurrency\n * ci(check): make installation of `taplo-cli` faster\n * fix(notifications): delete unnecessary Download(Pop/Push)Unit notifications\n * fix(downloads): extract closure for downloading a component into a separate function\n * feat(downloads): concurrently download components\n * fix(downloads): add a comment to justify the unwrap on `.get()` of `OnceLock`\n * chore(deps): update actions/checkout action to v5\n * fix(download_timeout): introduce RUSTUP_DOWNLOAD_TIMEOUT for overriding download timeout\n * fix(downloads): substitute the LazyLock for a OnceLock\n * feat(rustup_mode): revise help message\n * feat: improve error message for `rustup which`\n * test: detach snapshots from component installation order\n * feat(download_tracker): refactor in favor of `indicatif`\n * feat(process): create a `ProgressDrawTarget` (for `indicatif`) inside the `Process`\n * fix(rustup-init/sh): avoid `hw.optional.*: 1` stdout in macOS arch check\n * hack(cli/common): suppress host emulation warnings in rustup\u0027s own CI\n * fix(test/clitools): pass `RUSTUP_CI` to in-process tests\n * ci(macos): run x64 workflows with Rosetta 2\n * docs(user-guide/environment-variables): clarify the unit of `RUSTUP_UNPACK_RAM`\n * docs(user-guide/environment-variables): unify description style\n * docs(user-guide/environment-variables): update description of `RUSTUP_IO_THREADS`\n * Limit Tokio worker threads to I/O thread count\n * Use manual Tokio runtime setup\n * Attach io_thread_count() to Process\n * Always consider RUSTUP_IO_THREADS as input for thread count\n * utils: express io_thread_count() in a simpler way\n * opt(err): show renaming file error source\n * Set a maximum thread limit for remove_dir_all\n * fix(toolchain/distributable): refine handling of known targets with no prebuilt artifacts\n * fix(ci/fetch-rust-docker): update comments\n * fix(ci/docker): update `CC` name for `powerpc64le-unknown-linux-gnu`\n * Extract self_update() from update_all_channels()\n * Show channel updates even if self update is not permitted\n * Remove Cargo feature indirection\n * Move Cfg::get_self_update_mode() to SelfUpdateMode::from_cfg()\n * Replace trivial enum with bool\n * feat(updates): introduce `RUSTUP_TERM_WIDTH` to override terminal width\n * feat(updates): introduce `RUSTUP_TERM_PROGRESS_WHEN` to toggle the progress bars\n * Limit the default number of I/O threads\n * Bump `toml` to 0.9\n * feat(updates): check for updates concurrently\n * feat(terminal): implement the `TermLike` trait for `ColorableTerminal`\n * chore: use match ergonomics in favor of explicit `ref`s\n * refactor(download/curl): use early returns in `download()`\n * chore(cli/rustup_mode): merge `std` imports\n * chore(cli/rustup-mode): import `std::io`\n * chore: fix new `clippy` warnings\n * fix(ci/run): specify target triple for `bindgen-cli` installation\n * feat(www): improve \"copy\" button style compatibility with Chromium\n * ci(run): install `codegen-cli` with `cargo-binstall`\n * docs: replace Discord links\n * Block broken snap curl\n * Upgrade to windows-sys 0.60\n * Emphasize that `llvm-tools` dist component is not subject to compiler stability guarantees\n * docs(README): update CI status badge\n * Fix rustup-init.sh cputype check for sparcv9\n * add Solaris support\n * test(clitools)!: remove all deprecated `.expect_*()` APIs\n * test(clitools)!: privatize `Config::run()`\n * test: migrate remaining uses of `.run()` to `.expect()` APIs\n * test(clitools): extract `Assert::redact()`\n * test: simplify `.display().to_string()` in `.extend_redactions()`\n * test(cli_misc): bring back missing assertions\n * Update help.rs: bash completions instructions (#1)\n * docs(user-guide): fix typo\n * docs(dev-guide): update the section on `clippy` lints\n * docs(dev-guide): mention test helpers and `Assert`\n * docs(test/clitools): add docs for `Assert`\n * Upgrade to rustls-platform-verifier 0.6\n * test(cli-v2): migrate to `.expect()` APIs\n * test(cli-misc): migrate to `.expect()` APIs\n * fix(toolchain): fix proxy fallback notification format on Windows\n * test(cli-v1): migrate to `.expect()` APIs\n * test(download): serialize tests with proxy-sensitive URLs\n * test(cli-rustup): migrate to `.expect()` APIs\n * test(clitool): add `Assert::remove_redactions()`\n * test(clitools): allow `OsStr`-like args in `Config::expect*()`\n * Fix CI image names for downloading ARM and PowerPC artifacts\n * Update platforms to 3.6\n * test(cli-exact): migrate to `.expect()` APIs\n * Avoid swallowing errors in show()\n * Simplify target processing logic\n * Inline returned bindings\n * Increase Windows main thread stack size to 2mb\n * test(cli-inst-interactive): migrate to `.expect()` APIs\n * Unset RUSTUP_AUTO_INSTALL for tests\n * test(cli-paths): migrate to `.expect()` APIs\n * test(cli-exact): use the new `[CURRENT_VERSION]` redaction\n * test(cli-self-upd): migrate to `.expect()` APIs\n * Tweak list_items() docstring\n * Leverage bool::then_some() to simplify some code\n * Avoid intermediate allocation in listing\n * test(custom-toolchains): `target list` now can display the installed targets\n * feat(custom-toolchains): `target` and `component list` working on custom toolchains\n * Skip manifest loading if there are no components/targets to check\n * fix(deps): update rust crate opener to 0.8.0\n * rustup check: set exit status based on available updates\n * rustup check: adopt no-self-update logic\n * feat(self_update): add proxy sanity checks\n * style(test): qualify uses of `snapbox::str![]`\n * refactor(test): migrate some tests to `.expect()` APIs\n * chore(test): deprecated old APIs overlapping with the new ones\n * refactor(test): add new `.expect()`-based testing APIs\n * test(custom-toolchains): using `show` on a custom toolchain without a `components` file\n * test(custom-toolchains): add test to showcase that the issue was solved\n * feat(custom-toolchains): `rustup show` now reporting installed targets\n * tests: print diffs on test failures\n * Log versions during self updates\n * Fix cargo lints on Windows\n * toolchain: hoist binary name conditionals out of fallback functions\n * refactor(test): replace `TempDir::into_path()` with `TempDir::keep()`\n * refactor(test/clitools): use globally-defined `tempdir_in_with_prefix()`\n * feat(toolchain): notify the user when proxy fallback is activated\n * feat(toolchain): consider external `rust-analyzer` when calling a proxy\n * refactor(toolchain): move predicates into `Toolchain::maybe_do_cargo_fallback()`\n * refactor(toolchain): privatize `Toolchain::maybe_do_cargo_fallback()`\n * deps: update aws-lc-rs to 1.13.1\n * docs(changelog): mirror changes from the release announcement, take 2\n * Deprecate native-tls as well\n * Enable HTTP/2 support for reqwest download backend\n * Emit tracing events from log facade calls\n * download: show Debug representation for errors\n * Avoid repeated globals in tracing events\n * Log original download errors immediately\n * feat(cli/rustup-mode): add aliases to `rustup component remove`\n * Switch flate2 to use the zlib-rs backend\n * Hardlink proxies if symlinks aren\u0027t reachable\n * Add powerpc64le-unknown-linux-musl support\n * Add toolchain_name to not installed bail msg\n * Warn about using curl\n * Drop workspace indirection\n * Fold download crate back into rustup\n * download: merge integration test files\n * Test CARGO environment replacement\n * Update CARGO env var if it is a rustup proxy\n * Tweak toolchain subcommand help text\n * Move toolchain and default commands first\n * show toolchain paths in rustup show -v output\n * refactor(cli/self-update): save allocations in `Nu::rcfiles()`\n * fix(cli/self-update)!: stop appending to `env.nu` due to deprecation\n * fix(cli/self-update): consider Windows paths in Nushell suggestions\n * refactor(cli/self-update): use `path add` in `env.nu` template\n * fix(cli/self-update): use interpolated string in `env.nu` template\n * Upgrade dependencies\n * docs(user-guide/environment-variables): document `RUSTUP_VERSION`\n * feat(rustup-init/sh): allow setting `RUSTUP_VERSION` during installation\n * feat(cli/self-update): allow setting `RUSTUP_VERSION` for arbitrary\n downgrades\n * feat(test/clitools): add `Config::expect_ok_ex_env()`\n * fix(errors)!: improve error messages for `RustupError::ToolchainNotInstalled`\n * Add set auto-install disable\n * Use `cursor: pointer` for copy button on website\n * fix(dist): refine suggestions about missing targets\n * Append Windows bin directory to PATH by default\n * Remove validation for custom toolchains when reading rust-toolchain.toml\n * document RUSTUP_AUTO_INSTALL\n * Fix build script `cargo` instructions\n",
"title": "Description of the patch"
},
{
"category": "details",
"text": "openSUSE-Leap-16.0-1824",
"title": "Patchnames"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "SUSE ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "self",
"summary": "URL of this CSAF notice",
"url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_22016-1.json"
},
{
"category": "self",
"summary": "SUSE Bug 1230032",
"url": "https://bugzilla.suse.com/1230032"
},
{
"category": "self",
"summary": "SUSE Bug 1243862",
"url": "https://bugzilla.suse.com/1243862"
},
{
"category": "self",
"summary": "SUSE Bug 1249008",
"url": "https://bugzilla.suse.com/1249008"
},
{
"category": "self",
"summary": "SUSE Bug 1257902",
"url": "https://bugzilla.suse.com/1257902"
},
{
"category": "self",
"summary": "SUSE Bug 1270186",
"url": "https://bugzilla.suse.com/1270186"
},
{
"category": "self",
"summary": "SUSE Bug 1270521",
"url": "https://bugzilla.suse.com/1270521"
},
{
"category": "self",
"summary": "SUSE Bug 1270619",
"url": "https://bugzilla.suse.com/1270619"
},
{
"category": "self",
"summary": "SUSE Bug 1270644",
"url": "https://bugzilla.suse.com/1270644"
},
{
"category": "self",
"summary": "SUSE Bug 1270795",
"url": "https://bugzilla.suse.com/1270795"
},
{
"category": "self",
"summary": "SUSE Bug 1270870",
"url": "https://bugzilla.suse.com/1270870"
},
{
"category": "self",
"summary": "SUSE Bug 1270874",
"url": "https://bugzilla.suse.com/1270874"
},
{
"category": "self",
"summary": "SUSE Bug 1270989",
"url": "https://bugzilla.suse.com/1270989"
},
{
"category": "self",
"summary": "SUSE Bug 1274144",
"url": "https://bugzilla.suse.com/1274144"
},
{
"category": "self",
"summary": "SUSE Bug 1282217",
"url": "https://bugzilla.suse.com/1282217"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2024-12224 page",
"url": "https://www.suse.com/security/cve/CVE-2024-12224/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2025-58160 page",
"url": "https://www.suse.com/security/cve/CVE-2025-58160/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-25541 page",
"url": "https://www.suse.com/security/cve/CVE-2026-25541/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-25727 page",
"url": "https://www.suse.com/security/cve/CVE-2026-25727/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-41676 page",
"url": "https://www.suse.com/security/cve/CVE-2026-41676/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-41677 page",
"url": "https://www.suse.com/security/cve/CVE-2026-41677/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-41678 page",
"url": "https://www.suse.com/security/cve/CVE-2026-41678/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-41681 page",
"url": "https://www.suse.com/security/cve/CVE-2026-41681/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-41898 page",
"url": "https://www.suse.com/security/cve/CVE-2026-41898/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-42327 page",
"url": "https://www.suse.com/security/cve/CVE-2026-42327/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-44662 page",
"url": "https://www.suse.com/security/cve/CVE-2026-44662/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-45784 page",
"url": "https://www.suse.com/security/cve/CVE-2026-45784/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-93599 page",
"url": "https://www.suse.com/security/cve/CVE-2026-93599/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-93600 page",
"url": "https://www.suse.com/security/cve/CVE-2026-93600/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-93601 page",
"url": "https://www.suse.com/security/cve/CVE-2026-93601/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-93602 page",
"url": "https://www.suse.com/security/cve/CVE-2026-93602/"
}
],
"title": "Security update for rustup",
"tracking": {
"current_release_date": "2026-10-03T16:17:05Z",
"generator": {
"date": "2026-10-02T19:31:21Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf.pl",
"version": "1"
}
},
"id": "openSUSE-SU-2026:22016-1",
"initial_release_date": "2026-10-02T19:31:21Z",
"revision_history": [
{
"date": "2026-10-02T19:31:21Z",
"number": "1",
"summary": "Current version"
},
{
"date": "2026-10-03T16:17:05Z",
"number": "2",
"summary": "unknown changes"
}
],
"status": "final",
"version": "2"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "rustup-0:1.29.1~0-160000.1.1.aarch64",
"product": {
"name": "rustup-0:1.29.1~0-160000.1.1.aarch64",
"product_id": "rustup-0:1.29.1~0-160000.1.1.aarch64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/rustup@1.29.1~0-160000.1.1?arch=aarch64\u0026upstream=rustup-0:1.29.1~0-160000.1.1.src.rpm"
}
}
}
],
"category": "architecture",
"name": "aarch64"
},
{
"branches": [
{
"category": "product_version",
"name": "rustup-0:1.29.1~0-160000.1.1.x86_64",
"product": {
"name": "rustup-0:1.29.1~0-160000.1.1.x86_64",
"product_id": "rustup-0:1.29.1~0-160000.1.1.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/rustup@1.29.1~0-160000.1.1?arch=x86_64\u0026upstream=rustup-0:1.29.1~0-160000.1.1.src.rpm"
}
}
}
],
"category": "architecture",
"name": "x86_64"
},
{
"branches": [
{
"category": "product_name",
"name": "openSUSE Leap 16.0",
"product": {
"name": "openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0"
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "rustup-0:1.29.1~0-160000.1.1.aarch64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64"
},
"product_reference": "rustup-0:1.29.1~0-160000.1.1.aarch64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "rustup-0:1.29.1~0-160000.1.1.x86_64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
},
"product_reference": "rustup-0:1.29.1~0-160000.1.1.x86_64",
"relates_to_product_reference": "openSUSE Leap 16.0"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2024-12224",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2024-12224"
}
],
"notes": [
{
"category": "general",
"text": "Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2024-12224",
"url": "https://www.suse.com/security/cve/CVE-2024-12224"
},
{
"category": "external",
"summary": "SUSE Bug 1243848 for CVE-2024-12224",
"url": "https://bugzilla.suse.com/1243848"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.2,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "moderate"
}
],
"title": "CVE-2024-12224"
},
{
"cve": "CVE-2025-58160",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2025-58160"
}
],
"notes": [
{
"category": "general",
"text": "tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2025-58160",
"url": "https://www.suse.com/security/cve/CVE-2025-58160"
},
{
"category": "external",
"summary": "SUSE Bug 1249007 for CVE-2025-58160",
"url": "https://bugzilla.suse.com/1249007"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.1,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "low"
}
],
"title": "CVE-2025-58160"
},
{
"cve": "CVE-2026-25541",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-25541"
}
],
"notes": [
{
"category": "general",
"text": "Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition \"v_capacity \u003e= new_cap + offset\" uses an unchecked addition. When new_cap + offset overflows usize in release builds, this condition may incorrectly pass, causing self.cap to be set to a value that exceeds the actual allocated capacity. Subsequent APIs such as spare_capacity_mut() then trust this corrupted cap value and may create out-of-bounds slices, leading to UB. This behavior is observable in release builds (integer overflow wraps), whereas debug builds panic due to overflow checks. This issue has been patched in version 1.11.1.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-25541",
"url": "https://www.suse.com/security/cve/CVE-2026-25541"
},
{
"category": "external",
"summary": "SUSE Bug 1271347 for CVE-2026-25541",
"url": "https://bugzilla.suse.com/1271347"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "important"
}
],
"title": "CVE-2026-25541"
},
{
"cve": "CVE-2026-25727",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-25727"
}
],
"notes": [
{
"category": "general",
"text": "time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-25727",
"url": "https://www.suse.com/security/cve/CVE-2026-25727"
},
{
"category": "external",
"summary": "SUSE Bug 1257901 for CVE-2026-25727",
"url": "https://bugzilla.suse.com/1257901"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "important"
}
],
"title": "CVE-2026-25727"
},
{
"cve": "CVE-2026-41676",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-41676"
}
],
"notes": [
{
"category": "general",
"text": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-extract ignore the incoming *keylen, unconditionally writing the full shared secret (32/56/prime-size bytes). A caller passing a short slice gets a heap/stack overflow from safe code. OpenSSL 3.x providers do check, so this only impacts older OpenSSL. This vulnerability is fixed in 0.10.78.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-41676",
"url": "https://www.suse.com/security/cve/CVE-2026-41676"
},
{
"category": "external",
"summary": "SUSE Bug 1270137 for CVE-2026-41676",
"url": "https://bugzilla.suse.com/1270137"
},
{
"category": "external",
"summary": "SUSE Bug 1271911 for CVE-2026-41676",
"url": "https://bugzilla.suse.com/1271911"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "moderate"
}
],
"title": "CVE-2026-41676"
},
{
"cve": "CVE-2026-41677",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-41677"
}
],
"notes": [
{
"category": "general",
"text": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user\u0027s callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-41677",
"url": "https://www.suse.com/security/cve/CVE-2026-41677"
},
{
"category": "external",
"summary": "SUSE Bug 1270540 for CVE-2026-41677",
"url": "https://bugzilla.suse.com/1270540"
},
{
"category": "external",
"summary": "SUSE Bug 1271911 for CVE-2026-41677",
"url": "https://bugzilla.suse.com/1271911"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "moderate"
}
],
"title": "CVE-2026-41677"
},
{
"cve": "CVE-2026-41678",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-41678"
}
],
"notes": [
{
"category": "general",
"text": "rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 \u003c= in_.len(), but this condition is reversed. The intended invariant is out.len() \u003e= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of out by in_.len() - 8 - out.len() bytes, causing an out-of-bounds write from a safe public function. This vulnerability is fixed in 0.10.78.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-41678",
"url": "https://www.suse.com/security/cve/CVE-2026-41678"
},
{
"category": "external",
"summary": "SUSE Bug 1270641 for CVE-2026-41678",
"url": "https://bugzilla.suse.com/1270641"
},
{
"category": "external",
"summary": "SUSE Bug 1271911 for CVE-2026-41678",
"url": "https://bugzilla.suse.com/1271911"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "important"
}
],
"title": "CVE-2026-41678"
},
{
"cve": "CVE-2026-41681",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-41681"
}
],
"notes": [
{
"category": "general",
"text": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the stack. This is reachable from safe Rust. This vulnerability is fixed in 0.10.78.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-41681",
"url": "https://www.suse.com/security/cve/CVE-2026-41681"
},
{
"category": "external",
"summary": "SUSE Bug 1270719 for CVE-2026-41681",
"url": "https://bugzilla.suse.com/1270719"
},
{
"category": "external",
"summary": "SUSE Bug 1271911 for CVE-2026-41681",
"url": "https://bugzilla.suse.com/1271911"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "moderate"
}
],
"title": "CVE-2026-41681"
},
{
"cve": "CVE-2026-41898",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-41898"
}
],
"notes": [
{
"category": "general",
"text": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure\u0027s returned usize directly to OpenSSL without checking it against the \u0026mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in 0.10.78.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-41898",
"url": "https://www.suse.com/security/cve/CVE-2026-41898"
},
{
"category": "external",
"summary": "SUSE Bug 1270798 for CVE-2026-41898",
"url": "https://bugzilla.suse.com/1270798"
},
{
"category": "external",
"summary": "SUSE Bug 1271911 for CVE-2026-41898",
"url": "https://bugzilla.suse.com/1271911"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "moderate"
}
],
"title": "CVE-2026-41898"
},
{
"cve": "CVE-2026-42327",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-42327"
}
],
"notes": [
{
"category": "general",
"text": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate\u0027s AIA extension as OpensslString, whose Deref\u003cTarget = str\u003e wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a \u0026str that violates the UTF-8 invariant - resulting in undefined behavior. This vulnerability is fixed in 0.10.79.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-42327",
"url": "https://www.suse.com/security/cve/CVE-2026-42327"
},
{
"category": "external",
"summary": "SUSE Bug 1270454 for CVE-2026-42327",
"url": "https://bugzilla.suse.com/1270454"
},
{
"category": "external",
"summary": "SUSE Bug 1271911 for CVE-2026-42327",
"url": "https://bugzilla.suse.com/1271911"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "important"
}
],
"title": "CVE-2026-42327"
},
{
"cve": "CVE-2026-44662",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-44662"
}
],
"notes": [
{
"category": "general",
"text": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_aes_{128,192,256}_wrap_pad). For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller\u0027s buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This only impacts users using AES key-wrap-with-padding ciphers. This vulnerability is fixed in 0.10.79.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-44662",
"url": "https://www.suse.com/security/cve/CVE-2026-44662"
},
{
"category": "external",
"summary": "SUSE Bug 1270872 for CVE-2026-44662",
"url": "https://bugzilla.suse.com/1270872"
},
{
"category": "external",
"summary": "SUSE Bug 1271911 for CVE-2026-44662",
"url": "https://bugzilla.suse.com/1271911"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "moderate"
}
],
"title": "CVE-2026-44662"
},
{
"cve": "CVE-2026-45784",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-45784"
}
],
"notes": [
{
"category": "general",
"text": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller\u0027s buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-45784",
"url": "https://www.suse.com/security/cve/CVE-2026-45784"
},
{
"category": "external",
"summary": "SUSE Bug 1270946 for CVE-2026-45784",
"url": "https://bugzilla.suse.com/1270946"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "moderate"
}
],
"title": "CVE-2026-45784"
},
{
"cve": "CVE-2026-93599",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-93599"
}
],
"notes": [
{
"category": "general",
"text": "rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero padding bits and no data bytes), so raw_bits.len() - 1 underflows on the empty slice and the subsequent index operation panics (subtract-with-overflow in debug, index-out-of-bounds in release). The condition is reachable through the public API BorrowedCertRevocationList::from_der() when a CRL contains an issuingDistributionPoint extension with such an onlySomeReasons value. Exploitation requires an application that explicitly opts in to CRL revocation checking by passing RevocationOptions to verify_for_usage() and that parses CRL bytes obtained from a source the attacker can influence; the default rustls configuration, which does not use RevocationOptions, is unaffected. A crafted CRL causes a denial of service via the panic. Fixed in 0.103.13 and 0.104.0-alpha.7.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-93599",
"url": "https://www.suse.com/security/cve/CVE-2026-93599"
},
{
"category": "external",
"summary": "SUSE Bug 1282202 for CVE-2026-93599",
"url": "https://bugzilla.suse.com/1282202"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "important"
}
],
"title": "CVE-2026-93599"
},
{
"cve": "CVE-2026-93600",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-93600"
}
],
"notes": [
{
"category": "general",
"text": "rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Because name constraints are restrictions on otherwise properly issued certificates, the flaw is only reachable after successful signature verification and requires a misissued certificate to exploit; the library also provides no API for asserting URI names, and URI name constraints are otherwise unimplemented. Versions 0.103.12 and 0.104.0-alpha.6 reject URI name constraints unconditionally.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-93600",
"url": "https://www.suse.com/security/cve/CVE-2026-93600"
},
{
"category": "external",
"summary": "SUSE Bug 1282202 for CVE-2026-93600",
"url": "https://bugzilla.suse.com/1282202"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 2.2,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "important"
}
],
"title": "CVE-2026-93600"
},
{
"cve": "CVE-2026-93601",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-93601"
}
],
"notes": [
{
"category": "general",
"text": "rustls-webpki (the Rust webpki fork used by rustls) versions \u003e= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name constraint of accept.example.com was treated as satisfied by a certificate for *.example.com, which could feasibly assert reject.example.com - a name outside the permitted subtree. Because name constraints are restrictions applied to otherwise properly issued certificates, the issue is only reachable after signature verification succeeds and requires a misissued wildcard certificate to exploit.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-93601",
"url": "https://www.suse.com/security/cve/CVE-2026-93601"
},
{
"category": "external",
"summary": "SUSE Bug 1282202 for CVE-2026-93601",
"url": "https://bugzilla.suse.com/1282202"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "important"
}
],
"title": "CVE-2026-93601"
},
{
"cve": "CVE-2026-93602",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-93602"
}
],
"notes": [
{
"category": "general",
"text": "rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL\u0027s IssuingDistributionPoint, ignoring additional distributionPoints. Attackers with a compromised trusted issuing authority can present revoked certificates that pass revocation checks under UnknownStatusPolicy::Allow, or cause incorrect errors under the default deny policy.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-93602",
"url": "https://www.suse.com/security/cve/CVE-2026-93602"
},
{
"category": "external",
"summary": "SUSE Bug 1282202 for CVE-2026-93602",
"url": "https://bugzilla.suse.com/1282202"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.aarch64",
"openSUSE Leap 16.0:rustup-0:1.29.1~0-160000.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T19:31:21Z",
"details": "important"
}
],
"title": "CVE-2026-93602"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…