Bug 2542292 - CVE-2026-100866 rust-onefetch: onefetch: Terminal escape sequence injection via unsanitized manifest fields [fedora-all]
Summary: CVE-2026-100866 rust-onefetch: onefetch: Terminal escape sequence injection v...
Keywords:
Status: ASSIGNED
Alias: None
Product: Fedora
Classification: Fedora
Component: rust-onefetch
Version: rawhide
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Ben Beasley
QA Contact:
URL:
Whiteboard: {"flaws": ["33e6205e-da98-4248-9aed-2...
: 2542295 2542296 2542297 (view as bug list)
Depends On:
Blocks: CVE-2026-100866
TreeView+ depends on / blocked
 
Reported: 2026-09-28 03:36 UTC by Ganesh
Modified: 2026-09-28 06:28 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github o2sh onefetch issues 1828 0 None open Info field values aren't stripped of terminal escape sequences 2026-09-28 06:28:33 UTC

Description Ganesh 2026-09-28 03:36:25 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.

Comment 1 Ben Beasley 2026-09-28 06:27:50 UTC
*** Bug 2542297 has been marked as a duplicate of this bug. ***

Comment 2 Ben Beasley 2026-09-28 06:27:57 UTC
*** Bug 2542296 has been marked as a duplicate of this bug. ***

Comment 3 Ben Beasley 2026-09-28 06:28:09 UTC
*** Bug 2542295 has been marked as a duplicate of this bug. ***

Comment 4 Ben Beasley 2026-09-28 06:28:33 UTC
I am monitoring the upstream bug https://github.com/o2sh/onefetch/issues/1828 and the proposed fix in https://github.com/o2sh/onefetch/pull/1829. I am inclined to allow a little more time for discussion to run its course, and ideally for the fix to be at least merged upstream, before applying a downstream patch.

Since the proposed fix is in the main onefetch crate, corresponding to the rust-onefetch package, I’m closing bugs filed against rust-onefetch-ascii, rust-onefetch-image, and rust-onefetch-manifest.


Note You need to log in before you can comment on or make changes to this bug.