Lucene search

K
almalinuxAlmaLinuxALSA-2021:1935
HistoryMay 18, 2021 - 6:26 a.m.

Low: rust-toolset:rhel8 security, bug fix, and enhancement update

2021-05-1806:26:06
errata.almalinux.org
14
rust
security update
bug fix
enhancement
cve-2020-36318
cve-2020-36317
vecdeque::make_contiguous
string::retain()
almalinux.

EPSS

0.003

Percentile

70.3%

Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety.

The following packages have been upgraded to a later upstream version: rust (1.49.0). (BZ#1896712)

Security Fix(es):

  • rust: use-after-free or double free in VecDeque::make_contiguous (CVE-2020-36318)

  • rust: memory safety violation in String::retain() (CVE-2020-36317)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.