Bug 2449545

Summary: CVE-2026-32766 uv: astral-tokio-tar: Potential archive misinterpretation via malformed PAX extensions [epel-10]
Product: [Fedora] Fedora EPEL Reporter: Sandipan Roy <saroy>
Component: uvAssignee: Ben Beasley <code>
Status: ON_QA --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: epel10CC: code, mhroncok, python-packagers-sig, rust-sig
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["17e742de-f4e7-4c0e-895f-3a64399248be"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2448054, 2449243    
Bug Blocks: 2449371    

Description Sandipan Roy 2026-03-20 08:52:39 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Ben Beasley 2026-03-20 10:12:42 UTC
See https://www.cve.org/CVERecord?id=CVE-2026-32766. This is fixed in astral-tokio-tar 0.6.0, https://src.fedoraproject.org/rpms/rust-astral-tokio-tar/pull-request/3, which must be shipped together with uv 0.10.12 (released yesterday). I expect to be able to make updates for the EPEL10 leading branch within the next few days, possibly as soon as today.

I do *not* plan to fix this in EPEL10.2 and EPEL10.1 release branches, because (unlike in Fedora stable branches) there is no blanket Update Policy exception for updating Rust crate libraries across SemVer boundaries, and it’s not worth the time and effort I would have to invest in petitioning for an individual exception to cover this case.

Comment 2 Fedora Update System 2026-03-21 20:57:47 UTC
FEDORA-EPEL-2026-ea6f432357 (maturin-1.9.6-4.el10_3, rust-astral-tokio-tar-0.6.0-1.el10_3, and 3 more) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ea6f432357

Comment 3 Fedora Update System 2026-03-22 01:46:25 UTC
FEDORA-EPEL-2026-ea6f432357 has been pushed to the Fedora EPEL 10.3 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ea6f432357

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.