Bug 2449545 - CVE-2026-32766 uv: astral-tokio-tar: Potential archive misinterpretation via malformed PAX extensions [epel-10]
Summary: CVE-2026-32766 uv: astral-tokio-tar: Potential archive misinterpretation via ...
Keywords:
Status: ON_QA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: uv
Version: epel10
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Ben Beasley
QA Contact:
URL:
Whiteboard: {"flaws": ["17e742de-f4e7-4c0e-895f-3...
Depends On: 2448054 2449243
Blocks: CVE-2026-32766
TreeView+ depends on / blocked
 
Reported: 2026-03-20 08:52 UTC by Sandipan Roy
Modified: 2026-03-22 01:46 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2026-03-20 08:52:39 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Ben Beasley 2026-03-20 10:12:42 UTC
See https://www.cve.org/CVERecord?id=CVE-2026-32766. This is fixed in astral-tokio-tar 0.6.0, https://src.fedoraproject.org/rpms/rust-astral-tokio-tar/pull-request/3, which must be shipped together with uv 0.10.12 (released yesterday). I expect to be able to make updates for the EPEL10 leading branch within the next few days, possibly as soon as today.

I do *not* plan to fix this in EPEL10.2 and EPEL10.1 release branches, because (unlike in Fedora stable branches) there is no blanket Update Policy exception for updating Rust crate libraries across SemVer boundaries, and it’s not worth the time and effort I would have to invest in petitioning for an individual exception to cover this case.

Comment 2 Fedora Update System 2026-03-21 20:57:47 UTC
FEDORA-EPEL-2026-ea6f432357 (maturin-1.9.6-4.el10_3, rust-astral-tokio-tar-0.6.0-1.el10_3, and 3 more) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ea6f432357

Comment 3 Fedora Update System 2026-03-22 01:46:25 UTC
FEDORA-EPEL-2026-ea6f432357 has been pushed to the Fedora EPEL 10.3 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ea6f432357

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.


Note You need to log in before you can comment on or make changes to this bug.