Skip to content

[High] Patch rust for CVE-2026-40034, CVE-2026-5222, CVE-2026-5223#17625

Draft
BinduSri-6522866 wants to merge 4 commits into
microsoft:fasttrack/3.0from
Kanishk-Bansal:topic/CVE-2026-40034/CVE-2026-5222/CVE-2026-5223/rust-3.0
Draft

[High] Patch rust for CVE-2026-40034, CVE-2026-5222, CVE-2026-5223#17625
BinduSri-6522866 wants to merge 4 commits into
microsoft:fasttrack/3.0from
Kanishk-Bansal:topic/CVE-2026-40034/CVE-2026-5222/CVE-2026-5223/rust-3.0

Conversation

@BinduSri-6522866
Copy link
Copy Markdown

@BinduSri-6522866 BinduSri-6522866 commented Jun 4, 2026

Summary
Patch rust for CVE-2026-40034, CVE-2026-5222 and CVE-2026-5223

  • Backported CVE-2026-40034 by adapting the upstream gix-submodule fix to the older vendored gix-config::string_filter API in Rust 1.75

Change Log

  • modified: SPECS-EXTENDED/rust-cbindgen/rust-cbindgen.spec
  • modified: SPECS-EXTENDED/tardev-snapshotter/tardev-snapshotter.spec
  • modified: SPECS/clamav/clamav.spec
  • modified: SPECS/cloud-hypervisor/cloud-hypervisor.spec
  • modified: SPECS/flux/flux.spec
  • modified: SPECS/influxdb/influxdb.spec
  • modified: SPECS/kata-containers-cc/kata-containers-cc.spec
  • modified: SPECS/kata-containers/kata-containers.spec
  • modified: SPECS/librsvg2/librsvg2.spec
  • modified: SPECS/mesa/mesa.spec
  • modified: SPECS/netavark/netavark.spec
  • modified: SPECS/rpm-ostree/rpm-ostree.spec
  • new file: SPECS/rust/CVE-2026-40034.patch
  • new file: SPECS/rust/CVE-2026-5222.patch
  • new file: SPECS/rust/CVE-2026-5223.patch
  • new file: SPECS/rust/CVE-2026-40034_1.75.patch
  • new file: SPECS/rust/CVE-2026-5222_1.75.patch
  • new file: SPECS/rust/CVE-2026-5223_1.75.patch
  • modified: SPECS/rust/rust-1.75.spec
  • modified: SPECS/rust/rust.spec

Does this affect the toolchain?
NO

Links to CVEs
https://nvd.nist.gov/vuln/detail/CVE-2026-5222
https://nvd.nist.gov/vuln/detail/CVE-2026-5223
https://nvd.nist.gov/vuln/detail/CVE-2026-40034

Test Methodology
Buddy build:

@microsoft-github-policy-service microsoft-github-policy-service Bot added Packaging fasttrack/3.0 PRs Destined for Azure Linux 3.0 labels Jun 4, 2026
@BinduSri-6522866 BinduSri-6522866 changed the title [High] Patch for CVE-2026-40034, CVE-2026-5222, CVE-2026-5223 [High] Patch rust for CVE-2026-40034, CVE-2026-5222, CVE-2026-5223 Jun 4, 2026
@microsoft-github-policy-service microsoft-github-policy-service Bot added the specs-extended PR to fix SPECS-EXTENDED label Jun 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fasttrack/3.0 PRs Destined for Azure Linux 3.0 Packaging specs-extended PR to fix SPECS-EXTENDED

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant