Lucene search

K
osvGoogleOSV:RLSA-2021:1935
HistoryMay 18, 2021 - 6:26 a.m.

Low: rust-toolset:rhel8 security, bug fix, and enhancement update

2021-05-1806:26:06
Google
osv.dev
2
rust programming language
systems programming
thread safety
security fix
memory safety
cve-2020-36318
cve-2020-36317
cvss score
rocky linux 8.4

AI Score

7

Confidence

Low

EPSS

0.003

Percentile

70.3%

Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety.

The following packages have been upgraded to a later upstream version: rust (1.49.0). (BZ#1896712)

Security Fix(es):

  • rust: use-after-free or double free in VecDeque::make_contiguous (CVE-2020-36318)

  • rust: memory safety violation in String::retain() (CVE-2020-36317)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.4 Release Notes linked from the References section.