Fedora Rust-Cargo Information Disclosure Vulnerabilities 2026

Fedora Rust-Cargo Information Disclosure Vulnerabilities 2026

First seen 27 Aug 2026, 03:38 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Multiple information disclosure vulnerabilities have been identified in Fedora's Rust-Cargo packages, primarily affecting versions 0.10.24 and earlier. The vulnerabilities, cataloged under CVE-2026-5222, arise from a URL normalization flaw that could potentially expose sensitive data. Affected systems include Fedora 43 and 44, with updates released to mitigate these risks. The vulnerabilities were disclosed on May 25, 2026, and have since been addressed with patches. Users are advised to update their systems using the 'dnf' package manager to the latest versions. The updates include various packages related to Rust-Cargo, which are critical for managing Rust dependencies. The advisory emphasizes the importance of applying these updates promptly to safeguard against potential exploitation.

Key Points: • CVE-2026-5222 affects Fedora Rust-Cargo versions 0.10.24 and earlier. • The vulnerabilities stem from a URL normalization flaw leading to information disclosure. • Patches are available, and users should update their systems immediately.

Timeline

2026-05-25
CVE-2026-5222 published
Information disclosure vulnerability identified in Rust-Cargo due to URL normalization flaw.
Linuxsecurity
2026-08-18
Updates released for Fedora Rust-Cargo
Fedora released updates to address CVE-2026-5222, including cargo-c version 0.10.24 and related packages.
Linuxsecurity
2026-08-27
Advisories published on vulnerabilities
Multiple advisories were published detailing the vulnerabilities and urging users to apply updates.
Linuxsecurity