White Rabbitx 🏴☠️[verified]@TheRabbitPyDisclosure
The post announces CVE-2026-33056, detailing how malicious crates can change directory permissions during Cargo builds and urges updating Cargo and auditing dependencies. No PoC, exploit, or active exploitation is reported.
White Rabbitx 🏴☠️[verified]@TheRabbitPyDisclosure
The post discloses CVE‑2026‑33056, a Rust tar crate vulnerability that lets malicious crates modify build‑time directory permissions, but it offers no PoC, exploit, or mitigation details.
Jeremy Morgan[verified]@JeremyCMorganPatch
Rust has disclosed CVE-2026-33056, a vulnerability in the tar crate allowing permission changes during build-time extraction, and plans a fix in Rust 1.94.1 released on March 26.
ThreatCluster[verified]@threatclusterPatch
Fedora 42 and 43 have released a patch via dnf for CVE-2026-33056, a critical StGit flaw that allows crafted tar archives to arbitrarily change directory permissions.
Michael Martino[verified]@battista212Patch
CVE-2026-33056 lets malicious Rust packages alter file permissions during extraction, but has not been actively exploited yet. A patch is included in Rust 1.94.1 (due March 26); users should upgrade immediately.
ThreatCluster[verified]@threatclusterPatch
This announcement highlights that Fedora 44 has addressed the critical CVE-2026-33056 affecting its sched_ext BPF schedulers, urging users to update to rust-tar 0.4.45 to mitigate the vulnerability.
ThreatCluster[verified]@threatclusterPatch
Fedora 42 has released updates to mitigate CVE‑2026‑33056 by rebuilding Rust components, and while details of the vulnerability type are implied, no PoC or active exploitation is reported.
Michael[verified]@woollardm8Disclosure
The input references a Rust blog post about CVE-2026-33056, but no substantive details are provided in the text to confirm any specific indicators.