Bug 2542293 - CVE-2026-100866 rust-onefetch-image: onefetch: Terminal escape sequence injection via unsanitized manifest fields [epel-all]
Summary: CVE-2026-100866 rust-onefetch-image: onefetch: Terminal escape sequence injec...
Keywords:
Status: CLOSED DUPLICATE of bug 2542294
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: rust-onefetch-image
Version: epel10
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Ben Beasley
QA Contact:
URL:
Whiteboard: {"flaws": ["33e6205e-da98-4248-9aed-2...
Depends On:
Blocks: CVE-2026-100866
TreeView+ depends on / blocked
 
Reported: 2026-09-28 03:36 UTC by Ganesh
Modified: 2026-09-28 06:29 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-09-28 06:29:16 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github o2sh onefetch issues 1828 0 None open Info field values aren't stripped of terminal escape sequences 2026-09-28 06:29:15 UTC

Description Ganesh 2026-09-28 03:36:30 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.

Comment 1 Ben Beasley 2026-09-28 06:29:16 UTC
I am monitoring the upstream bug https://github.com/o2sh/onefetch/issues/1828 and the proposed fix in https://github.com/o2sh/onefetch/pull/1829. I am inclined to allow a little more time for discussion to run its course, and ideally for the fix to be at least merged upstream, before applying a downstream patch.

Since the proposed fix is in the main onefetch crate, corresponding to the rust-onefetch package, I’m closing bugs filed against rust-onefetch-ascii, rust-onefetch-image, and rust-onefetch-manifest.

*** This bug has been marked as a duplicate of bug 2542294 ***


Note You need to log in before you can comment on or make changes to this bug.