Your message dated Sat, 25 Jul 2026 11:48:39 +0000
with message-id <[email protected]>
and subject line Bug#1135225: fixed in rustc 1.85.1+dfsg1-1+deb13u1
has caused the Debian Bug report #1135225,
regarding rust-tar: CVE-2026-33055
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1135225: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1135225
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: rust-tar
Version: 0.4.44-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for rust-tar.
CVE-2026-33055[0]:
| tar-rs is a tar archive reading/writing library for Rust. Versions
| 0.4.44 and below have conditional logic that skips the PAX size
| header in cases where the base header size is nonzero. As part of
| CVE-2025-62518, the astral-tokio-tar project was changed to
| correctly honor PAX size headers in the case where it was different
| from the base header. This is almost the inverse of the astral-
| tokio-tar issue. Any discrepancy in how tar parsers honor file size
| can be used to create archives that appear differently when unpacked
| by different archivers. In this case, the tar-rs (Rust tar) crate is
| an outlier in checking for the header size - other tar parsers
| (including e.g. Go archive/tar) unconditionally use the PAX size
| override. This can affect anything that uses the tar crate to parse
| archives and expects to have a consistent view with other parsers.
| This issue has been fixed in version 0.4.45.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-33055
https://www.cve.org/CVERecord?id=CVE-2026-33055
[1]
https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-gchp-q4r4-x4ff
[2]
https://github.com/alexcrichton/tar-rs/commit/de1a5870e603758f430073688691165f21a33946
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: rustc
Source-Version: 1.85.1+dfsg1-1+deb13u1
Done: Fabian Grünbichler <[email protected]>
We believe that the bug you reported is fixed in the latest version of
rustc, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Fabian Grünbichler <[email protected]> (supplier of updated
rustc package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 24 Jul 2026 18:02:33 +0200
Source: rustc
Architecture: source
Version: 1.85.1+dfsg1-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian Rust Maintainers
<[email protected]>
Changed-By: Fabian Grünbichler <[email protected]>
Closes: 1135220 1135225
Changes:
rustc (1.85.1+dfsg1-1+deb13u1) trixie; urgency=medium
.
* New upstream point release 1.85.1 (Closes: #1135220)
- fix doctest merging with edition 2024
- fix rustdoc on 32-bit ARM
* backport tar CVE-2026-33055/CVE-2026-33056 fixes (Closes: #1135225)
* cherry-pick cargo CVE-2026-5222/CVE-2026-5223 fixes
Checksums-Sha1:
0ad0536bf9e52993d2eb5321e61996c8e371c647 4393 rustc_1.85.1+dfsg1-1+deb13u1.dsc
af0d5fbe39f5a1097852c697c3b36b40b9940a17 230724
rustc_1.85.1+dfsg1.orig-extra.tar.xz
58d263f19818a7e256cf2cee3c00b7e2edbf5948 82979912
rustc_1.85.1+dfsg1.orig.tar.xz
5e5ec2dd701391df3d532c0b65b6a9e452f8d7c1 150364
rustc_1.85.1+dfsg1-1+deb13u1.debian.tar.xz
862d5720cb879ba8886e30a902b17d8a81cd7d8f 10294
rustc_1.85.1+dfsg1-1+deb13u1_source.buildinfo
Checksums-Sha256:
b1ad5619fd417f5a6f2ea9b80f911733bb8872e52e3b2f045fd0529417f45be2 4393
rustc_1.85.1+dfsg1-1+deb13u1.dsc
664df803dead620ebe459dc37fae7a5bc4aabe09d9bae0dd81762ea18225a36d 230724
rustc_1.85.1+dfsg1.orig-extra.tar.xz
97153151aeee78416f595a4200b17c3713d271960f3bad91a44f2afaf0bb7799 82979912
rustc_1.85.1+dfsg1.orig.tar.xz
5cd897ba67287ea3d58c2c8f5be6c90c0a3ad7cd890f55e16c595a92a4db352f 150364
rustc_1.85.1+dfsg1-1+deb13u1.debian.tar.xz
ed995f8eddcc77e63e619ae2d3ad79d19595cc744014df648549a753a7a8ee9e 10294
rustc_1.85.1+dfsg1-1+deb13u1_source.buildinfo
Files:
d6bd9d3dc4950d5cbd17abfff7c5f661 4393 devel optional
rustc_1.85.1+dfsg1-1+deb13u1.dsc
0697e6e2b9073ef65845af85971053f9 230724 devel optional
rustc_1.85.1+dfsg1.orig-extra.tar.xz
33f34b1ab07007016e365c5c0e601771 82979912 devel optional
rustc_1.85.1+dfsg1.orig.tar.xz
bb92a7f3c5c487164a71f38b07c38607 150364 devel optional
rustc_1.85.1+dfsg1-1+deb13u1.debian.tar.xz
d6a7dbd33b921adc6f8c5c262b0562a7 10294 devel optional
rustc_1.85.1+dfsg1-1+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJVBAEBCgA/FiEEbdkGe7ToK0Amc9ppdh5TKjcTRTAFAmpkVLUhHGRlYmlhbkBm
YWJpYW4uZ3J1ZW5iaWNobGVyLmVtYWlsAAoJEHYeUyo3E0UwzzMP/3OuIIETwP/T
Pb2gWAQ5/jXAma2bWQBQ7yBpo2XbGGISN2NIg8YqfEP/fXQCtDM91GqeRzGpmlmx
eajEFvzMbwyp+eFDnRacU5HdK3gzjYXaT2Jcjsusfm6wRGCx69bHK1zo1RpSjIZC
4OG1u8sISrsPficy4Jl081sg8MeNB8zSQ9172B+HJ0eCYlPVzl8aWG2i42RY5UE9
b5DcZAQt1vz2g3KMiKSlQ9KZoDzFurvCZM37O5KSqIuG5Jj5iBzxg5QOMpCgB3FB
+Zsccv+nbuF5ZjlHwIUFqONT+1hol7DLVjeBIiMSqFTwd7RutUcSCHDQCYuG8mjf
zWXeSqUxKqoMOq/X3kLsJVz61deH+JD7cUNdCBIP/ajPwgzS1VRuASesRwutg1oE
OXC5+mHPFz8iMPkvo2ssPBgT5YVJCb1tNr/u2iSz76SdegIvj3sd3SvpZlVPBW7+
7IKWH2iVxSgjDYnzxDAUq/NuMQyJg42aEV0EG+wdc+7KrQmDJ6sJFHIDuPlOSy7M
K4VPft6KKJyqD3FrFGC5eKbBlU9glr9jzJwS7lwB0nqVeXSPLGXD2feJWTbkdKSG
AqismM6A02LamVjmnk/zN+Hqg/bdxrmQ3WcTSZx4Ho4NURJYlTR0YOL0VADvBHvK
59/Hu+XpWLqAWwVJH3SXLuGyGd5mgTuz
=skYa
-----END PGP SIGNATURE-----
pgp9ACcPxeZat.pgp
Description: PGP signature
--- End Message ---