Skip to content
Fedora 42: rust-tikv-jemallocator Critical CVE-2025

Fedora 42: rust-tikv-jemallocator Critical CVE-2025

Linuxsecurity •LinuxSecurity Advisories • November 3, 2025

A Rust allocator backed by jemalloc. Update Information : uv 0.9.5 Since uv was built with astral-tokio-tar 0.5.6, this is a security fix for CVE-2025-62518. ruff 0.14.2 rust-astral-tokio-tar 0.5.6 Fixed a parser desynchronization vulnerability when reading tar archives that contain mismatched size information in PAX/ustar headers. This vulnerability is being tracked as GHSA-j5gw-2vrg-8fgx and CVE-2025-62518. Initial package for python-uv-build in Fedora 42 Initial packages for a number of new dependencies for ruff and uv Update rust-tikv-jemallocator and rust-tikv-jemalloc-sys to 0.6.1 Update openapi-python-client to 0.26.2 and patch it to allow ruff 0.14

A Rust allocator backed by jemalloc.

uv 0.9.5 Since uv was built with astral-tokio-tar 0.5.6, this is a security fix for CVE-2025-62518. ruff 0.14.2 rust-astral-tokio-tar 0.5.6 Fixed a parser desynchronization vulnerability when reading tar archives that contain mismatched size information in PAX/ustar headers. This vulnerability is being tracked as GHSA-j5gw-2vrg-8fgx and CVE-2025-62518. Initial package for python-uv-build in Fedora 42 Initial packages for a number of new dependencies for ruff and uv Update rust-tikv-jemallocator and rust-tikv-jemalloc-sys to 0.6.1 Update openapi-python-client to 0.26.2 and patch it to allow ruff 0.14

* Thu Oct 16 2025 Benjamin A. Beasley - 0.6.1-1 - Update to version 0.6.1; Fixes RHBZ#2404523 * Fri Jul 25 2025 Fedora Release Engineering - 0.6.0-2 - Rebuilt for

* Thu Oct 16 2025 Benjamin A. Beasley - 0.6.1-1 - Update to version 0.6.1; Fixes RHBZ#2404523 * Fri Jul 25 2025 Fedora Release Engineering - 0.6.0-2 - Rebuilt for

[ 1 ] Bug #2360699 - ruff-0.14.1 is available [ 2 ] Bug #2402441 - rust-reqsign-core-2.0.0 is available [ 3 ] Bug #2402442 - rust-reqsign-command-execute-tokio-2.0.0 is available [ 4 ] Bug #2402443 - rust-reqsign-http-send-reqwest-2.0.0 is available [ 5 ] Bug #2402881 - python-uv-build-0.9.5 is available [ 6 ] Bug #2402923 - uv-0.9.5 is available [ 7 ] Bug #2405474 - CVE-2025-62518 rust-astral-tokio-tar: astral-tokio-tar Vulnerable to PAX Header Desynchronization [fedora-42] [ 8 ] Bug #2405476 - CVE-2025-62518 uv: astral-tokio-tar Vulnerable... Read the Full Advisory

[ 1 ] Bug #2360699 - ruff-0.14.1 is available [ 2 ] Bug #2402441 - rust-reqsign-core-2.0.0 is available [ 3 ] Bug #2402442 - rust-reqsign-command-execute-tokio-2.0.0 is available [ 4 ] Bug #2402443 - rust-reqsign-http-send-reqwest-2.0.0 is available [ 5 ] Bug #2402881 - python-uv-build-0.9.5 is available [ 6 ] Bug #2402923 - uv-0.9.5 is available [ 7 ] Bug #2405474 - CVE-2025-62518 rust-astral-tokio-tar: astral-tokio-tar Vulnerable to PAX Header Desynchronization [fedora-42] [ 8 ] Bug #2405476 - CVE-2025-62518 uv: astral-tokio-tar Vulnerable...

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a77c1f005b' at the command line. For more information, refer to the dnf documentation available at

Extracted Entities

Platforms (1)

Vulnerabilities (1)