[CLSA-2026:1790785797] Fix CVE(s): CVE-2026-5222, CVE-2026-5223
Type:
security
Severity:
Moderate
Release date:
2026-09-30 16:30:13 UTC
Description:
* SECURITY UPDATE: credential scope confusion between sparse registry URLs differing only by a .git suffix - debian/patches/CVE-2026-5222.patch: skip the GitHub lower-casing and the .git-suffix stripping in CanonicalUrl::new when the URL scheme contains a '+', so sparse+https://host/index and sparse+https://host/index.git no longer canonicalize to the same registry and share credentials - CVE-2026-5222
Updated packages:
  • cargo1.86_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_amd64.deb
    sha:c721fb076aefe481ff6cc2622059c8af78a82bbf
  • cargo1.86-doc_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_all.deb
    sha:f423d04a150306fb3dca0abedddc68c43a16696f
  • libstd-rust1.86-1.86_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_amd64.deb
    sha:5228aa0b6c43fa684077bfca3b755e7dbe1798a5
  • libstd-rust1.86-dev_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_amd64.deb
    sha:201703f57f7d646ab7859c6029fc233bdf90922f
  • rust1.86-all_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_all.deb
    sha:f5988001f72f1cc304ba5f2d21331680db725985
  • rust1.86-analyzer_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_amd64.deb
    sha:3749bcb3d8b71510498d2ebf8d00dc9b46a0af61
  • rust1.86-clippy_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_amd64.deb
    sha:185c3cbd3bb204d2d918a2d8e4b0a605be7ab6b3
  • rust1.86-doc_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_all.deb
    sha:406810a4d8efba1171214930f60e922a10d272c0
  • rust1.86-gdb_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_all.deb
    sha:65cfb9c12859da71ad2d8075345b71ac63a9cd74
  • rust1.86-lldb_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_all.deb
    sha:bb2b83df8f41248be31840d4563cffe9bbb18e24
  • rust1.86-llvm_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_amd64.deb
    sha:9788fa8a4d1e73b0a49ae20c8c877795abf1868d
  • rust1.86-src_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_all.deb
    sha:cee8b93ce955aeb2cb55bd35ec6ca864daf008db
  • rustc1.86_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_amd64.deb
    sha:a60bc59305be72aaef6a7da6c4e80021049d5789
  • rustfmt1.86_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_amd64.deb
    sha:d5fcc3eb146a143a1e0245386037ebc3ac2fecb2
  • cargo1.86_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_arm64.deb
    sha:c30d9aea86a4f16b352018bb3a53ca02055c19b4
  • libstd-rust1.86-1.86_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_arm64.deb
    sha:9b11ea73b5577e61358ac91aab5963b00a3868f5
  • libstd-rust1.86-dev_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_arm64.deb
    sha:7666035461b6f822be3bff8b926015a0414d35b1
  • rust1.86-analyzer_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_arm64.deb
    sha:b7cec96ad8c2bee031fc408c130008195dd985c2
  • rust1.86-clippy_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_arm64.deb
    sha:013a350384e1bbe2075d2c1c996ce235e5bd6a3d
  • rust1.86-llvm_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_arm64.deb
    sha:4c6c78c0cab5da0a10d515991dba95ed7c6fc1ac
  • rustc1.86_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_arm64.deb
    sha:89e5e1a76c09848ee585717d123f421ec03a96e7
  • rustfmt1.86_1.86.0+dfsg1-1~bpo13+2+tuxcare.els7_arm64.deb
    sha:0501527c1f023d385b7a0bbeffd20582bcdbcfac
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.