[Git][security-tracker-team/security-tracker][master] Track fix via unstable for CVE-2026-6654/rust-thin-vec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Apr 30 06:41:04 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e61bf5c9 by Salvatore Bonaccorso at 2026-04-30T07:40:19+02:00
Track fix via unstable for CVE-2026-6654/rust-thin-vec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5381,7 +5381,7 @@ CVE-2026-5928 (Calling the ungetwc function on a FILE stream with wide character
CVE-2026-6662 (A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The imp ...)
NOT-FOR-US: ericc-ch copilot-api
CVE-2026-6654 (Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVe ...)
- - rust-thin-vec <unfixed> (bug #1134494)
+ - rust-thin-vec 0.2.17-1 (bug #1134494)
[trixie] - rust-thin-vec <no-dsa> (Minor issue)
NOTE: https://github.com/mozilla/thin-vec/security/advisories/GHSA-xphw-cqx3-667j
NOTE: Fixed by: https://github.com/mozilla/thin-vec/commit/df64748355222525c344ecd9d2c9f59a662e1678 (v0.2.16)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e61bf5c95f3e377d6c6f1e5a5305eced005870c0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e61bf5c95f3e377d6c6f1e5a5305eced005870c0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260430/af133998/attachment.htm>
More information about the debian-security-tracker-commits
mailing list