Bug 2449545
| Summary: | CVE-2026-32766 uv: astral-tokio-tar: Potential archive misinterpretation via malformed PAX extensions [epel-10] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora EPEL | Reporter: | Sandipan Roy <saroy> |
| Component: | uv | Assignee: | Ben Beasley <code> |
| Status: | ON_QA --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | epel10 | CC: | code, mhroncok, python-packagers-sig, rust-sig |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["17e742de-f4e7-4c0e-895f-3a64399248be"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2448054, 2449243 | ||
| Bug Blocks: | 2449371 | ||
|
Description
Sandipan Roy
2026-03-20 08:52:39 UTC
See https://www.cve.org/CVERecord?id=CVE-2026-32766. This is fixed in astral-tokio-tar 0.6.0, https://src.fedoraproject.org/rpms/rust-astral-tokio-tar/pull-request/3, which must be shipped together with uv 0.10.12 (released yesterday). I expect to be able to make updates for the EPEL10 leading branch within the next few days, possibly as soon as today. I do *not* plan to fix this in EPEL10.2 and EPEL10.1 release branches, because (unlike in Fedora stable branches) there is no blanket Update Policy exception for updating Rust crate libraries across SemVer boundaries, and it’s not worth the time and effort I would have to invest in petitioning for an individual exception to cover this case. FEDORA-EPEL-2026-ea6f432357 (maturin-1.9.6-4.el10_3, rust-astral-tokio-tar-0.6.0-1.el10_3, and 3 more) has been submitted as an update to Fedora EPEL 10.3. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ea6f432357 FEDORA-EPEL-2026-ea6f432357 has been pushed to the Fedora EPEL 10.3 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ea6f432357 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. |