[Pkg-rust-maintainers] Bug#1093883: rust-gix-worktree-state: CVE-2025-22620

Moritz Mühlenhoff jmm at inutil.org
Thu Jan 23 19:03:12 GMT 2025


Source: rust-gix-worktree-state
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for rust-gix-worktree-state.

CVE-2025-22620[0]:
| gitoxide is an implementation of git written in Rust. Prior to
| 0.17.0, gix-worktree-state specifies 0777 permissions when checking
| out executable files, intending that the umask will restrict them
| appropriately. But one of the strategies it uses to set permissions
| is not subject to the umask. This causes files in a repository to be
| world-writable in some situations. This vulnerability is fixed in
| 0.17.0.

https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-fqmf-w4xh-33rh
https://rustsec.org/advisories/RUSTSEC-2025-0001.html


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-22620
    https://www.cve.org/CVERecord?id=CVE-2025-22620

Please adjust the affected versions in the BTS as needed.



More information about the Pkg-rust-maintainers mailing list