[Pkg-rust-maintainers] Bug#1149888: rust-gix-fs: CVE-2026-100419

Salvatore Bonaccorso carnil at debian.org
Sat Oct 3 22:50:07 BST 2026


Source: rust-gix-fs
Version: 0.22.1-1
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security upstream

Hi,

The following vulnerability was published for rust-gix-fs.

CVE-2026-100419[0]:
| gitoxide gix-fs before 0.23.0 contains a path validation bypass
| vulnerability in the worktree checkout mechanism that allows
| attackers to escape the worktree directory via symlink manipulation.
| During forced checkout with overwrite_existing enabled, attackers
| can craft malicious repository trees where symlink entries replace
| validated directories, causing subsequent files to be written
| outside the worktree through the symlink for code execution or file
| manipulation.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-100419
    https://www.cve.org/CVERecord?id=CVE-2026-100419
[1] https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5
[2] https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Pkg-rust-maintainers mailing list