[Bug 2154209] Re: CVE-2026-5223: Crates in third party registries can override the cached source of other crates

Finn Gärtner 2154209 at bugs.launchpad.net
Tue May 26 08:51:00 UTC 2026


** Also affects: rustc-1.93 (Ubuntu Resolute)
   Importance: Undecided
       Status: New

** Also affects: rustc-1.93 (Ubuntu Noble)
   Importance: Undecided
       Status: New

** Also affects: rustc-1.93 (Ubuntu Trusty)
   Importance: Undecided
       Status: New

** Also affects: rustc-1.93 (Ubuntu Jammy)
   Importance: Undecided
       Status: New

** Also affects: rustc-1.93 (Ubuntu Questing)
   Importance: Undecided
       Status: New

** Also affects: rustc-1.93 (Ubuntu Focal)
   Importance: Undecided
       Status: New

** Also affects: rustc-1.93 (Ubuntu Xenial)
   Importance: Undecided
       Status: New

** Also affects: rustc-1.93 (Ubuntu Bionic)
   Importance: Undecided
       Status: New

** Changed in: rustc-1.93 (Ubuntu)
     Assignee: (unassigned) => Finn Gärtner (finnrg)

** Changed in: rustc-1.93 (Ubuntu)
       Status: New => In Progress

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to rustc-1.93 in Ubuntu.
Matching subscriptions: rustc-1.93
https://bugs.launchpad.net/bugs/2154209

Title:
  CVE-2026-5223: Crates in third party registries can override the
  cached source of other crates

Status in rustc-1.93 package in Ubuntu:
  In Progress
Status in rustc-1.93 source package in Trusty:
  New
Status in rustc-1.93 source package in Xenial:
  New
Status in rustc-1.93 source package in Bionic:
  New
Status in rustc-1.93 source package in Focal:
  New
Status in rustc-1.93 source package in Jammy:
  New
Status in rustc-1.93 source package in Noble:
  New
Status in rustc-1.93 source package in Questing:
  New
Status in rustc-1.93 source package in Resolute:
  New

Bug description:
  A full description of this CVE can be found on the rust-lang blog[1].

  Cargo incorrectly handles symlinks inside of crate tarballs downloaded
  from third-party registries, allowing malicious crates to override the
  source code of another crate from the same registry.

  Starting with Rust 1.96.0, extracting any symlink within crate
  tarballs shall be rejected, so any Rust version before that is
  affected.

  [1]: https://blog.rust-lang.org/2026/05/25/cve-2026-5223/

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rustc-1.93/+bug/2154209/+subscriptions





More information about the foundations-bugs mailing list