On 2023-01-12 01:40, Alex Kiernan via lists.openembedded.org wrote:
Changes:
   Added validation of SSH host keys for git URLs in Cargo (CVE-2022-46176)

Thanks Alex!

According to:
  https://nvd.nist.gov/vuln/detail/CVE-2022-46176

  "All Rust versions containing Cargo before 1.66.1 are vulnerable. "

so we'll have to fix:

kirkstone and langdale.



Sundeep, Naveen, or anyone,

Please find out what the upstream Rust team's plan is for older releases.

If they aren't going to release a dot update, we'll have to start back-porting the patches
listed here:

https://github.com/rust-lang/wg-security-response/tree/main/patches/CVE-2022-46176

--
# Randy MacLeod
# Wind River Linux

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#175808): 
https://lists.openembedded.org/g/openembedded-core/message/175808
Mute This Topic: https://lists.openembedded.org/mt/96218038/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to