[Git][security-tracker-team/security-tracker][master] Track fix via unstable for CVE-2026-6654/rust-thin-vec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Apr 30 06:41:04 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e61bf5c9 by Salvatore Bonaccorso at 2026-04-30T07:40:19+02:00
Track fix via unstable for CVE-2026-6654/rust-thin-vec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5381,7 +5381,7 @@ CVE-2026-5928 (Calling the ungetwc function on a FILE stream with wide character
 CVE-2026-6662 (A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The imp ...)
 	NOT-FOR-US: ericc-ch copilot-api
 CVE-2026-6654 (Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVe ...)
-	- rust-thin-vec <unfixed> (bug #1134494)
+	- rust-thin-vec 0.2.17-1 (bug #1134494)
 	[trixie] - rust-thin-vec <no-dsa> (Minor issue)
 	NOTE: https://github.com/mozilla/thin-vec/security/advisories/GHSA-xphw-cqx3-667j
 	NOTE: Fixed by: https://github.com/mozilla/thin-vec/commit/df64748355222525c344ecd9d2c9f59a662e1678 (v0.2.16)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e61bf5c95f3e377d6c6f1e5a5305eced005870c0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e61bf5c95f3e377d6c6f1e5a5305eced005870c0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260430/af133998/attachment.htm>


More information about the debian-security-tracker-commits mailing list