PT-2026-29964 · Canonical · Rust-Cargo-C

Published

2026-04-01

·

Updated

2026-04-01

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
It was discovered that tar-rs embedded in cargo-c incorrectly handled symlinks when unpacking a tar archive. If a user or automated system were tricked into processing a specially crafted tar archive, a remote attacker could use this issue to modify permissions of arbitrary directories outside the extraction root, and possibly escalate privileges.

Related Identifiers

USN-8139-1

Affected Products

Rust-Cargo-C