Bug 2542292

Summary: CVE-2026-100866 rust-onefetch: onefetch: Terminal escape sequence injection via unsanitized manifest fields [fedora-all]
Product: [Fedora] Fedora Reporter: Ganesh <gnaik>
Component: rust-onefetchAssignee: Ben Beasley <code>
Status: ASSIGNED --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: rawhideCC: code, rust-sig
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["33e6205e-da98-4248-9aed-208c85404671"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2542074    

Description Ganesh 2026-09-28 03:36:25 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.

Comment 1 Ben Beasley 2026-09-28 06:27:50 UTC
*** Bug 2542297 has been marked as a duplicate of this bug. ***

Comment 2 Ben Beasley 2026-09-28 06:27:57 UTC
*** Bug 2542296 has been marked as a duplicate of this bug. ***

Comment 3 Ben Beasley 2026-09-28 06:28:09 UTC
*** Bug 2542295 has been marked as a duplicate of this bug. ***

Comment 4 Ben Beasley 2026-09-28 06:28:33 UTC
I am monitoring the upstream bug https://github.com/o2sh/onefetch/issues/1828 and the proposed fix in https://github.com/o2sh/onefetch/pull/1829. I am inclined to allow a little more time for discussion to run its course, and ideally for the fix to be at least merged upstream, before applying a downstream patch.

Since the proposed fix is in the main onefetch crate, corresponding to the rust-onefetch package, I’m closing bugs filed against rust-onefetch-ascii, rust-onefetch-image, and rust-onefetch-manifest.