[Git][security-tracker-team/security-tracker][master] Add CVE-2026-100419/rust-gix-fs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 26 21:37:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
88d2b911 by Salvatore Bonaccorso at 2026-09-26T22:36:32+02:00
Add CVE-2026-100419/rust-gix-fs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -605,7 +605,9 @@ CVE-2026-100502 (Flame through 2.4.0 contains an insufficient session expiration
 CVE-2026-100501 (Flame through 2.4.0 contains an improper restriction of excessive auth ...)
 	NOT-FOR-US: Flame
 CVE-2026-100419 (gitoxide gix-fs before 0.23.0 contains a path validation bypass vulner ...)
-	TODO: check
+	- rust-gix-fs <unfixed>
+	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5
+	NOTE: Fixed by: https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875 (gix-fs-v0.23.0)
 CVE-2026-100418 (Flame through 2.4.0 contains an information exposure vulnerability in  ...)
 	NOT-FOR-US: Flame
 CVE-2026-100417 (RustDesk before 1.5.0 on Windows fails to enforce the one-way file tra ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d2b91170e62dfb9e20efb224f3138350f9700f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d2b91170e62dfb9e20efb224f3138350f9700f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/3789b18f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list