[Pkg-rust-maintainers] Bug#1149888: rust-gix-fs: CVE-2026-100419
Salvatore Bonaccorso
carnil at debian.org
Sat Oct 3 22:50:07 BST 2026
Source: rust-gix-fs
Version: 0.22.1-1
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security upstream
Hi,
The following vulnerability was published for rust-gix-fs.
CVE-2026-100419[0]:
| gitoxide gix-fs before 0.23.0 contains a path validation bypass
| vulnerability in the worktree checkout mechanism that allows
| attackers to escape the worktree directory via symlink manipulation.
| During forced checkout with overwrite_existing enabled, attackers
| can craft malicious repository trees where symlink entries replace
| validated directories, causing subsequent files to be written
| outside the worktree through the symlink for code execution or file
| manipulation.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-100419
https://www.cve.org/CVERecord?id=CVE-2026-100419
[1] https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5
[2] https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the Pkg-rust-maintainers
mailing list