stable

rust-ambient-id-0.0.5-1.el10_1, rust-astral-tokio-tar-0.5.6-1.el10_1, & 17 more

FEDORA-EPEL-2025-e6cbc78be8 created by music 4 months ago for Fedora EPEL 10.1

uv 0.8.24

https://github.com/astral-sh/uv/blob/0.8.24/CHANGELOG.md

Since uv was built with astral-tokio-tar 0.5.6, this is a security fix for CVE-2025-62518.


rust-astral-tokio-tar 0.5.6

  • Fixed a parser desynchronization vulnerability when reading tar archives that contain mismatched size information in PAX/ustar headers.

    This vulnerability is being tracked as GHSA-j5gw-2vrg-8fgx and CVE-2025-62518.


Update rust-tikv-jemallocator and rust-tikv-jemalloc-sys to 0.6.1.


Initial packages for a number of new dependencies for uv, and initial EPEL10 packages for a few of their dependencies.

This update's test gating status has been changed to 'waiting'.

4 months ago

This update's test gating status has been changed to 'ignored'.

4 months ago

This update has been submitted for testing by bodhi.

4 months ago

This update has been pushed to testing.

4 months ago

music edited this update.

New build(s):

  • rust-tikv-jemallocator-0.6.1-1.el10_1
  • rust-tikv-jemalloc-sys-0.6.1-1.el10_1

Karma has been reset.

4 months ago

This update has been submitted for testing by music.

4 months ago

This update has been pushed to testing.

4 months ago

music edited this update.

New build(s):

  • rust-astral-tokio-tar-0.5.6-1.el10_1
  • rust-backon-1.5.2-2.el10_1

Karma has been reset.

4 months ago

This update has been submitted for testing by music.

4 months ago

music edited this update.

New build(s):

  • rust-reqsign-0.17.0-1.el10_1

Karma has been reset.

4 months ago

music edited this update.

New build(s):

  • rust-rust-ini-0.21.3-1.el10_1

Removed build(s):

  • rust-rust-ini-0.21.2-2.el10_1

Karma has been reset.

4 months ago

This update has been pushed to testing.

4 months ago

music edited this update.

New build(s):

  • uv-0.8.24-2.el10_1
  • rust-ambient-id-0.0.5-1.el10_1
  • rust-secrecy-0.10.3-1.el10_1

Karma has been reset.

4 months ago

This update has been submitted for testing by music.

4 months ago

This update has been pushed to testing.

4 months ago

music edited this update.

New build(s):

  • rust-backon-1.6.0-1.el10_1

Removed build(s):

  • rust-backon-1.5.2-2.el10_1

Karma has been reset.

4 months ago

This update has been submitted for testing by music.

4 months ago

music edited this update.

4 months ago
User Icon music commented & provided feedback 4 months ago

I’m going to try to stop editing this so that it can go stable.

This update has been pushed to testing.

4 months ago

This update has been submitted for stable by bodhi.

3 months ago

This update has been pushed to stable.

3 months ago

Please log in to add feedback.

BZ#2405468 CVE-2025-62518 rust-astral-tokio-tar: astral-tokio-tar Vulnerable to PAX Header Desynchronization [epel-10]
0
0
BZ#2405469 CVE-2025-62518 uv: astral-tokio-tar Vulnerable to PAX Header Desynchronization [epel-10]
0
0

Automated Test Results