{"id":"openSUSE-SU-2026:22016-1","summary":"Security update for rustup","details":"This update for rustup fixes the following issues:\n\n- CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243862).\n- CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249008).\n- CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes\n  (bsc#1274144).\n- CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion\n  (bsc#1257902).\n- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1\n  (bsc#1270186).\n- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-\n  openssl crate (bsc#1270619).\n- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270644).\n- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate\n  (bsc#1270795).\n- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent\n  memory in rust-openssl crate (bsc#1270870).\n- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate\n  (bsc#1270521).\n- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate\n  (bsc#1270874).\n- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-\n  openssl crate (bsc#1270989).\n- CVE-2026-93599: rustls-webpki: panic via empty BIT STRING (bsc#1282217).\n- CVE-2026-93600: rustls-webpki: name constraints URI validation bypass (bsc#1282217).\n- CVE-2026-93601: rustls-webpki: name constraint bypass (bsc#1282217).\n- CVE-2026-93602: rustls-webpki: CRL revocation check bypass (bsc#1282217).\n- rust-shlex: Multiple issues involving quote API (RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032).\n\nChanges for rustup:\n\n- Update to version 1.29.1~0:\n * dist(rustup-init/sh): update commit shasum in help string\n * style(bin/rustup-init): reformat code\n * docs(changelog): update for v1.29.1 stable release\n * warn how to switch away from the deprecated complete profile\n * fix(cli/help): fix wording in `rustup run --help`\n * ci(docker/android): stop building OpenSSL\n * refactor(cli/docs): use tracing for docs opening status messages\n * refactor(self-update): rename Windows uninstall registry helpers\n * feat(test): isolate Windows registry state per test\n * docs(dev-guide): mention how to support new compilation targets\n * Fix funding link\n * chore(deps): lock file maintenance\n * refactor(cli/self-update): move `current_install_opts()` to `InstallOpts::display()`\n * refactor(cli/self-update): move `process` out of `InstallOpts`\n * fix(cli/self-update): postpone initialization of `Cfg` in `setup_mode`\n * refactor(cli/self-update): take `Process` in `check_existence_of_settings_file()`\n * fix(settings): prevent creating new file with `SettingsFile::read_settings()`\n * test(cli-inst-interactive): test file creation on cancelled installation\n * refactor(toolchain/names): inline `validate()` aliases into `FromStr`\n * refactor(toolchain/names): rename `validate()` to `normalize_name()`\n * fix minor typos\n * www: align copy icon\n * refactor(toolchain/names)!: remove `try_from_str!()`\n * refactor(toolchain/names)!: remove `from_variant!()`\n * Add `rustup doc --serve` to serve docs over local HTTP\n * Move doc() and man() into a new docs module\n * chore(github): comment out instructions in PR template\n * docs(dev-guide): reapply abandoned changes from #4970\n * Add riscv64 unknown linux musl support\n * fix(deps): update rust crate enum-map to v3\n * refactor(cli/self-update)!: rename `install()` to `InstallOpts::install()`\n * refactor(cli/self-update)!: rename `maybe_install_rust()` to `InstallOpts::install_rust()`\n * refactor(cli/self-update)!: rename `InstallOpts::install()` to `InstallOpts::select_toolchain()`\n * refactor(toolchain/names)!: make more clones during conversions explicit\n * refactor(cli/self-update): move message templates to `mod msg`\n * style(cli/self-update): reorganize imports\n * Add pull request template linking to the dev guide\n * doc: add AI policy to the dev guide\n * ci(dist): ensure pushing to `dev-static` on `stable` update\n * test(toolchain): add a test case for `rustup toolchain install --override`\n * feat(toolchain): add `--default` flag to `rustup toolchain install`\n * fix(toolchain): inline use of `set_override`\n * Add Enzyme to the list of rustup components\n * fix: repair toolchains without an installed manifest\n * refactor: expose the installed manifest path\n * Docs: Remove i686 `set default-host` example\n * fix(self-update): only remove complete profile lines\n * chore(deps): bump `platforms` to 4.1.0\n * chore(deps): remove pinned `openssl-src`\n * refactor: replace `cfg_if!{}` with `cfg_select!{}`\n * fix: Lock state file updates\n * Fix Rust 1.97 clippy warnings\n * uninstalls toolchains prior to deleting the rustup home folder\n * Take semver-compatible dependency updates\n * Upgrade platforms to 4\n * docs: update `CHANGELOG` for v1.29.1\n * Lock file maintenance\n * Remove Windows special case from `can_run`\n * diskio: drop unnecessary constructor wrapper\n * diskio: rename _IncrementalFileState to FileState\n * diskio: inline IncrementalFileState type alias\n * Minimize API visibility\n * toolchain: streamline validate() implementations\n * toolchain: avoid internal cloning\n * dist: drop unused conversion impl\n * dist: keep impls with type definitions\n * Don't hide allocations inside From impls\n * toolchain: drop impls for &String\n * Warn on clippy::or_fun_call\n * Warn on clippy::needless_by_ref_mut\n * Warn on clippy::redundant_clone\n * Warn on clippy::manual_let_else\n * Warn on clippy::use_self\n * errors: box ToolchainDesc in RustupError variants\n * errors: box Manifest in RequestedComponentsUnavailable variant\n * No (more) need to allow clippy::arc_with_non_send_sync\n * Replace use of FnMut trait objects with custom trait\n * test(cli/self-upd): use direct arg0 override for `as_rustup_setup()`\n * chore(deps): update actions/cache action to v6\n * ci(windows): add support for aarch64-pc-windows-gnullvm target\n * ci(windows): refine MSVC/MINGW job step predicates\n * chore(deps): update actions/checkout action to v7\n * fix(deps): update rust crate itertools to 0.15\n * fix(progress): use the `prefix` placeholder instead of `msg` for component name\n * rustup: warn when no toolchain or default is configured\n * errors: extract default stable hint\n * feat(toolchain): make the \"installed\" text of a toolchain install green\n * Add aarch64-unknown-freebsd\n * chore: address linter warnings\n * chore(deps): bump to semver-compatible versions\n * Add funding links\n * ci(docker/freebsd): bump `clang` version to `freebsd14`\n * ci(freebsd): use FreeBSD 14.0 for full CI\n * chore(deps): update `curl`\n * feat(cli/rustup-mode): warn about auto-installation in some subcommands\n * refactor(config): accept `Cfg` in `EnsureInstalled::warn_auto_install()`\n * test(cli/rustup-mode): test auto-installation on to-be-deprecated subcommand\n * dist: move display_name() before other methods that it calls\n * chore(gitignore): add .cargo/config.windows-cross.toml to gitignore\n * docs(dev-guide): update platform-specific code guidance\n * docs(dev-guide): mention rust-analyzer support for Windows-specific code on Unix\n * docs(dev-guide): mention how to lint Windows-specific code on Unix\n * chore(config): add example config for cross checking and rust-analyzer\n * chore: add rust-analyzer example config\n * Display the full names of targets not matching the host target tuple\n * docs(dev-guide/tips-and-tricks): mention the `RUSTUP_FORCE_ARG0='rustup'` cargo alias\n * build(cargo): add `cargo` alias for `RUSTUP_FORCE_ARG0='rustup'`\n * docs: rename the repath helper variable\n * Remove double buffering when extracting archives\n * refactor(toolchain/distributable): return `EnsureInstalled\u003c\u003e` from `DistributableToolchain::install()`\n * docs(dev-guide/coding-standards): adapt style guide from rustls\n * fix(deps): update opentelemetry\n * feat(config): warn user if auto-install is enabled\n * refactor(config): return `EnsureInstalled\u003c\u003e` from more functions\n * refactor(config): extract `EnsureInstalled\u003c\u003e` wrapper type\n * test: make tests agnostic to external `RUSTUP_AUTO_INSTALL` and `RUST_RECURSION_COUNT`\n * test(dist): fail v2 manifest update when manifest disagrees with .sha256\n * fix(dist): propagate v2 manifest checksum failure instead of reporting \"unchanged\"\n * Align shell setup comments in install message\n * feat(cli/self-update): refine wording of \"already installed Rust\" warning\n * chore(settings): rename default_host_triple to default_host_tuple and alias old name\n * chore(settings): add test to parse default_host_triple in toml\n * test(download): also scrub `HTTP_PROXY` in `scrub_env()`\n * chore: document legacy default host setting\n * chore: rename internal tuple constants\n * chore: rename partially \"Triple\" to \"Tuple\" to reflect the new terminology\n * fix(cli/rustup-mode)!: complete `rustup show` if active toolchain is not installed\n * refactor(cli/rustup-mode): postpone eval of `active_toolchain_targets` in `show()`\n * refactor(cli/rustup-mode): postpone eval of `active_toolchain` in `show()`\n * refactor(cli/rustup-mode): reduce rightward drift in `show()`\n * refactor(cli/rustup-mode): refine usage of `stdout` term and locks in `show()`\n * feat(config): add `Cfg` field to force-disable auto-installation\n * Provide --yes alias for -y flag consistently\n * refactor(tests): rename triple to tuple\n * refactor: bulk rename triple to ruple\n * refactor: rename get_default_host_triple to default_host_tuple\n * test(download): support more feature flag combinations\n * docs: fix the FileBuffer::clear doc comment wording\n * docs: fix plural of VM in coding standards\n * fix(dist): bulk rename triple to tuple for variables and messages\n * refactor(dist): rename PartialTargetTriple to PartialTargetTuple\n * refactor(dist): rename triple module to target_tuple\n * refactor: remove PartialToochainDesc::has_triple() in favor to PartialTargetTriple::is_empty()\n * refactor(dist): rename TargetTriple to TargetTuple\n * fix(self-update): rename triple to tuple in self_update\n * dist: bump `rustup` version to v1.29.1\n * ci(linux/x64-musl): install missing libc dependencies\n * fix(tests): rename HOST_TRIPLE placeholder to HOST_TUPLE\n * fix(tests): rename this_host_triple() to this_host_tuple()\n * fix(init): rename triple to tuple to reflect the new terminology\n * fix(docs): rename triple to tuple to reflect the new terminology\n * chore(deps): update ubuntu docker tag to v26\n * Improve error message for incomplete toolchains\n * chore(deps): update bwoodsend/setup-winlibs-action action to v1.16\n * test(dist/manifest): use the reordered fixture in `manifest_serialized_with_sorted_keys`\n * docs: fix \"initial\" spelling in stylesheet variable\n * ci: powerpc64-unknown-linux-musl is now stable\n * style(cli/rustup-mode): address clippy warnings\n * docs(dev-guide): update release process with new backporting flow\n * docs: fix actions template README typo\n * Only show post-install instructions for currently installed shells\n * docs: fix Windows MSVC guide typo\n * Upgrade to rustls-platform-verifier 0.7\n * Make component removal best-effort and preserve single-error behavior\n * Use `cc-rs` to detect the default linker, instead of assuming `cc`\n * ci(test): add `workflow_dispatch` trigger on par with `schedule`\n * ci: fix incorrect `contains()` predicate\n * fix(dist/manifestation): fix log format when installing exactly 2 components\n * Allow rustup component add to install multiple components in one update #4787\n * fix(docs): correct link to `no-self-update` feature\n * ci: enable on all PR target branches\n * ci(backport): rename backport branches to `release/*`\n * feat(toolchain): run a pre-check before updating all toolchains\n * feat(install): accept an optional pre-fetched manifest when installing\n * fix(toolchain): extract manifest fetching out of `show_dist_version()`\n * fix(manifest): aggregate a manifest and its hash in a `ManifestWithHash` struct\n * fix: Reduce flickering by using `set_move_cursor`\n * ci(backport): add support for backporting\n * fix: install message misalignment.\n * refactor: extracted `progress_style` method for DownloadStatus\n * fix(deps): update rust crate sha2 to 0.11\n * chore(doc): Added comments for clarify the usage of `Component::name` `Manifest::name` and the `short_name` funcc accordingly.\n * refactor: Rename `Component`'s `name_in_manifest` to `name` and `short_name` accordingly\n * self_update: show path to executable in case of updater failure\n * Revert \"fix(ci/freebsd): install ca certs to prevent certificate-related issues\"\n * ci: don't install protoc\n * Update to mdbook 0.5\n * ci(all-features): bump protoc version\n * fix(dist/manifestation): use full toolchain name in `Update::unavailable_components()`\n * style(dist/manifestation): merge imports\n * Fix zsh completion showing all PATH entries for +toolchain arg\n * fix(cli/proxy-mode): stop enforcing `quiet: true`\n * chore(deps/freebsd): downgrade `libz-sys` to v1.1.24\n * fix(ci/freebsd): install ca certs to prevent certificate-related issues\n * fix(rustup-init/sh): prevent passing `--default-host` twice\n * Avoid warning about the existence of a `settings.toml` on a fresh install\n * use tuple instead of triple for env overrides\n * Take platforms 3.9.0\n * Unpin tracing-subcriber\n * chore(deps): update `aws-lc-rs` and `aws-lc-sys`\n * docs(changelog): update release date for v1.29.0\n * docs(dev-guide/release-process): mention the CfT blog post\n * docs(changelog): update for v1.29.0 stable release\n * fix(cli): Style CLI errors in init mode\n * test: Add unknown arg init test\n * chore(deps): update actions/upload-artifact action to v7\n * refactor(www): simplify instruction css selector\n * feat(www): make copy button dark mode-aware\n * feat(www): move feedback text out of copy button\n * fix(www): apply filter to rust logo\n * feat(www): add dark mode\n * refactor(www): extract css variables\n * fix(cli/self-update): enforce a newline after `check_updates()`\n * refactor(cli/self-update): extract `has_progress_bars` in `check_updates()`\n * fix(cli/self-update): unify `check_*update*()`'s message formats\n * docs(downloads): fix the default number of `RUSTUP_CONCURRENT_DOWNLOADS`\n * feat(toolchain): add `--override` to override toolchain as soon as installed\n * fix(toolchain): improve logs when recovering from an interrupted installation\n * chore(deps): downgrade `openssl-src` to 300.5.4+3.5.4\n * style(download): clean up imports\n * fix(diskio): fall back to single-threaded unpacking when `ram_budget` \u003c 512MB to avoid OOM on memory-constrained systems\n * test(downloads): check if an error is thrown if the server does not honor range\n * fix(downloads): check correct response when resuming from partial (reqwest)\n * fix(downloads): check correct response when resuming from partial (curl)\n * fix(deps): update rust crate toml to v1\n * fix(dist/manifest): sort keys when serializing `Manifest`\n * hack(ci/linux): disable BuildKit when building local images\n * chore(ci): use more distinctive local image names\n * Upgrade rand to 0.10\n * Upgrade snapbox to 1\n * Upgrade to anstream 1\n * fix(downloads): adjust error message for partial files in network failures\n * test(downloads): ensure that partial files are not removed when network fails\n * feat(downloads): do not delete partial download when network fails\n * fix(downloads): substitute `DEK` alias for `DownloadError`\n * chore(deps): update aws-actions/configure-aws-credentials action to v6\n * cli: introduce semantic exit code constants for rustup check\n * Add missing Windows SDK instructions\n * Add winget instructions to MSVC install page\n * Remove nu-string-interpolation `$`\n * Replace $nu.home-path with ~\n * feat(cli/rustup-mode): add \"Exit status\" section to `rustup check --help`\n * Add common commands section in help text\n * fix(cli/rustup-mode): improve exit code of `rustup check`\n * refactor(test)!: pass status code directly to `SanitizedOutput`\n * Add powerpc64-unknown-linux-musl support\n * fix: add copy_file_symlink_to_source for self-installation\n * fix: preserve symlinks in copy_dir instead of following them\n * feat(cli/rustup-mode): add `doc --rustc-docs` to open rustdoc for Rust internals\n * Remove the mixed singular/plural phrasing as \"component(s)\" instead, use \"components\" or \"component\".\n   In the singular case also add the name of the component for more consistent messaging style with\n   other info! outputs about single components.\n * fix(cli/rustup-mode): `check` for self updates for `SelfUpdateMode::CheckOnly`\n * test: Add test for sequential multi-toolchain uninstall\n * fix: directory removal race condition in toolchain uninstall\n * test(cli_v2): test error when missing many components on install\n * fix(dist): adjust printed newlines in `components_missing_msg()`\n * unified nightly disclaimer wording/styling; preserved distinct messages per scenario\n * Upgrade to reqwest 0.13\n * change test name to match new terminology\n * rename file to match new terminology\n * change 'target triple' to 'target tuple'\n * fix(toolchain): forbid toolchain names starting with +\n * cli: add `doc --releases` to open release notes\n * chore(deps): update actions/upload-artifact action to v6\n * chore(deps): update actions/cache action to v5\n * dist: use more concise API in helper function\n * dist: inline more logic into helper function\n * dist: give helper function a more meaningful name\n * dist: move helper function closer to usage site\n * docs(dev-guide): mention snapshot updating in release process\n * fix(toolchain): avoid unwrapping when parsing a toolchain name\n * fix(toolchain): change regex to reject leading zeros in toolchain name\n * docs(changelog): update for v1.29.0 beta release\n * dist: bump `rustup` version to v1.29.0\n * docs(changelog): add missing link references\n * test(static-roots): use a more compact syntax for raw binaries\n * test(static-roots): return `Result` from `store_static_roots()`\n * download: statically bundle relevant trust anchors\n * Added xonsh support\n * refactor(dist/manifestation): remove redundant redeclarations\n * docs(dist/download): remove outdated note on concurrent download progress reporting\n * fix(dist/download): align `total_bytes` fields in progress reporting UI\n * fix: default to GNU host in Cygwin/MSYS/MinGW environments (#4221)\n * chore(config): remove redundant imports\n * fix(dist/manifestation): print \"downloading component\" only on `InstallEvents`\n * fix(utils): downgrade panic to warning in `delete_dir_contents_following_links()`\n * chore(deps): update actions/checkout action to v6\n * Prepare for mdbook 0.5 migration\n * dist: make installation asynchronous\n * dist: make installations 'static\n * dist: take ownership of Manifestation\n * dist: store owned temp::Context in Transaction\n * dist: store temp::Context in DownloadCfg\n * dist: align progress bar elements\n * dist: track progress during unpacking\n * utils: drop unused reader tracking\n * process: fix refresh rate for progress bars\n * process: reduce duplication in ProgressDrawTarget setup\n * Yield references from Manifest::short_name()\n * Move Component name helpers to Manifest\n * dist: simplify ComponentBinary construction\n * dist: hoist creation of io_executor some more\n * Move unpack_ram() from dist to diskio\n * dist: hoist Executor creation up\n * dist: inline effective RAM limit calculation\n * dist: hoist environment variable extraction\n * dist: use logging for missing parent warnings\n * dist: clarify dependency on unpack RAM budget\n * diskio: clarify dependency on I/O thread count\n * dist: transfer ownership of component values\n * dist: take ownership of existing Components\n * dist: take ownership of toolchain name in update()\n * dist: take ownership of manifest in update()\n * dist: derive trivial initialization for Update\n * dist: rename Update::build_update() to new()\n * dist: linearize for-loop in Update::build_update()\n * dist: inline single-use function\n * dist: inline trivial helper function\n * dist: inline single-use tranaction change helpers\n * dist: store specific config bit in Transaction\n * chore(config): migrate config .github/renovate.json\n * dist: attach manifest download functions to DownloadCfg\n * rustup: unhide top-level install/uninstall commands\n * dist: move update_from_dist() to DistOptions::install_into()\n * Be more consistent about aliases for different subcommands\n * test: add test for `rustup toolchain install --no-update`\n * feat(rustup-mode): add `no_update` flag to `rustup toolchain install`\n * cli: prepare DistOptions in advance\n * dist: inline trivial wrapper function\n * cli: inline single-use update_all_channels() helper\n * config: simplify update_all_channels()\n * dist: deduplicate DistOptions initialization\n * dist: avoid recomputing dist root URL\n * dist: simplify tracing instrumentation\n * install: take ownership in InstallMethod::install()\n * dist: move DistributableToolchain::install() up\n * dist: clarify when update_hash is available\n * cli: avoid dropped temporary\n * Take semver-compatible dependencies\n * dist: install while downloading\n * dist: store more context in ComponentBinary\n * dist: yield self when download is complete\n * dist: move URL alteration logic into DownloadCfg method\n * Apply suggestions from clippy 1.91\n * refactor(check): Consolidate use_colors checks\n * fix(check): Use Cargo's colors\n * refactor(check): Make calls more consistent\n * dist: drop another layer of abstraction\n * dist: store package directory once\n * dist: inline short single-use function\n * dist: discard unnecessary abstraction layer\n * chore(deps): update actions/upload-artifact action to v5\n * fix(cli/rustup-mode): add missing self-update in `rustup toolchain install`\n * refactor(cli/self-update): move `self_update()` to `SelfUpdateMode::update()`\n * refactor(cli/rustup-mode): pass self-update predicates into `self_update()`\n * refactor(cli/self-update): import `utils::ExitCode`\n * rustup: tweak update check output style\n * fix(list): Match show command's styling\n * test(list): Add UI test\n * fix(toolchain): Have 'list' match 'show's styling\n * refactor(toolchain): Order logic by display order\n * refactor(toolchain): Use string interpolation\n * test(toolchain): Show list's behavior\n * fix(update): Match 'cargo update's colors\n * refactor(update): Centralize style knowledge\n * test: Cover different show_channel_update cases\n * fix(check): Subject check to RUSTUP_TERM_COLOR\n * test(check): Show current style\n * fix: Use HEADER styling in 'rustup show'\n * chore: Update clap-cargo\n * test: Demonstrate show's behavior\n * test(process): Allow forcing color on\n * test(process): Ensure non-locked writes are stripped of ANSI escape codes\n * cli: update `uninstall_removes_source_from_rcs` to mirror `uninstall_doesnt_modify_rcs_with_no_modify_path`\n * cli: add tests for `rustup self uninstall --no-modify-path`\n * cli: add `rustup self uninstall --no-modify-path`\n * cli: add help text for `rustup self uninstall -y`\n * fix(cli/help): change indentation of discussions to 2 spaces\n * fix(cli/help): adjust help text for `rustup install`\n * feat(cli/help): add toolchain install tips to `rustup update`'s discussion\n * feat(cli/help): discuss `rustup toolchain install`\n * style: Remove wildcard imports\n * progress: modify progress bar's states to be column-aligned\n * installations: handle installation of components through progress bars\n * feat(cli): Add a sub-heading style for 'completion' Help Discussion\n * feat(cli): Have Help Discussions match rest of CLI Help\n * feat(cli): Add color to clap help/errors\n * refactor(cli): Switch help text to functions\n * cli: propagate ActiveSource from the top\n * cli: upgrade error events to ERROR level\n * cli: inline Cfg::active_rustc_version()\n * cli: extract display_version() from rustup main()\n * cli: inline Cfg::resolve_local_toolchain()\n * cli: inline Cfg::resolve_toolchain()\n * config: extract setting of toolchain override in rustup help mode\n * cli: avoid Cfg construction indirection\n * config: privatize some Cfg fields\n * config: drop trivial Cfg setters\n * Expand `RUSTUP_TOOLCHAIN_SOURCE`'s documentation\n * refactor(installation): extract installation of a component into a separate function\n * bin: clean up imports\n * cli: rename CLIError to CliError\n * config: rename OverrideDB to OverrideDb\n * dist: clean up unnecessary qualification\n * test: Replace trycmd with snapbox\n * chore: Update snapbox\n * Update the default Windows SDK version\n * refactor(log): Single source RUSTUP_TERM_COLOR\n * style: Encourage using existing imports\n * process: avoid fine-grained locking for logs\n * process: discard unnecessary layer of synchronization\n * process: inline TerminalInnerLocked\n * process: replace unsafe code with safe equivalent\n * process: extract color_choice() method\n * process: extract is_a_tty value\n * process: inline StreamSelector::is_a_tty()\n * process: inline TestWriterLock\n * Implement `RUSTUP_TOOLCHAIN_SOURCE` with new `Display` impl\n * Move `Display` impl to `to_reason()`\n * Rename `ActiveReason` to `ActiveSource`\n * dist: simplify DownloadStatus setup\n * dist: decentralize download status\n * dist: postpone creation of ComponentBinary values\n * dist: extract DownloadStatus type\n * dist: call DownloadTracker methods directly\n * dist: drop unnecessary Notifier layer\n * dist: replace PackageContext with DownloadCfg\n * refactor: Directly apply styling\n * refactor: Don't bother grabbing lock for tests\n * refactor: Replace termcolor with anstream\n * refactor: Move style building out of ColorableTerminal\n * refactor: Migrate to anstyle for color definitions\n * fix(www): removes www subdomain from all rust-lang.org urls\n * dist: move Notification into dist::download\n * notifications: remove unused Display impl\n * dist: move Notifier into DownloadCfg\n * cli: build Cfg earlier in setup mode\n * dist: reuse existing DownloadCfg in update_v1()\n * dist: move dist_root out of DownloadCfg\n * dist: drop unused Clone derives\n * dist: drop Copy derive from DownloadCfg\n * dist: move Notifier and DownloadTracker into dist::download\n * dist: inline DownloadCfg test setup\n * download: move File items down\n * download: extract DownloadCfg initialization from Cfg\n * config: discard pointless method argument\n * cli: rename DownloadTracker::new_with_display_progress() to new()\n * notifications: log directly from DownloadTracker\n * notifications: log directly on bad download checksums\n * notifications: log directly when reusing downloaded files\n * notifications: log directly on buffer size changes\n * Update platforms to 3.7.0\n * notifications: log directly on duplicate toolchain files\n * notifications: log directly on metadata upgrades that remove toolchains\n * notifications: log directly when reading metadata version\n * notifications: log directly when metadata upgrade is not needed\n * notifications: log directly when upgrading metadata version\n * notifications: log directly when uninstalling toolchains\n * notifications: log directly when toolchain is up to date\n * notifications: log directly when toolchain has been installed\n * notifications: log directly when installing toolchains\n * notifications: log the toolchain directory directly\n * notifications: log directly when using existing toolchains\n * notifications: log directly when looking for toolchains\n * notifications: log directly when setting auto-self-update mode\n * notifications: log directly when setting profile\n * notifications: log directly when setting overrides\n * notifications: use human-friendly log format for temp file deletions\n * notifications: use human-friendly log format for directory deletions\n * notifications: use human-friendly log format for retrying renames\n * notifications: use human-friendly log format for path canonicalization\n * cli: drop unnecessary generics\n * process: import instead of qualifying ColorableTerminal\n * process: hide internal structure\n * process: don't re-export external items\n * process: rename terminalsource to terminal_source\n * process: rename filesource to file_source\n * process: re-order items in terminalsource module\n * feat(cli/self-update): add support for PowerShell on Unix systems\n * refactor: Remove unused traits\n * refactor: Directly use ColorableTerminal\n * refactor: Simplify working with ColorableTerminal\n * fix(process): Ensure stdout/stderr lock is held across calls\n * refactor(process): Centralize Write bookkeeping\n * docs(changelog): describe default profile change during auto-install\n * Fix typo in clitools.rs comment\n * ci(docs): fix local doc branch name\n * Move the default branch from `master` to `main`\n * Upgrade opentelemetry dependencies\n * ci: use macOS Intel runners\n * notifications: log directly when setting the default toolchain\n * notifications: log directly when setting auto install mode\n * notifications: log directly when resuming partial downloads\n * notifications: log directly when downloading files\n * notifications: log directly when removing stray hash files\n * notifications: log directly when skipping components\n * notifications: log directly on missing components\n * notifications: log directly when downloading legacy manifests\n * notifications: log directly for downloaded manifests\n * notifications: log directly for manifest downloads\n * notifications: log directly when removing components\n * notifications: log directly when installing components\n * notifications: log directly after failing to determine memory limit\n * notifications: log directly when hash file not found\n * notifications: log directly when failing to update hash file\n * notifications: log directly when component is already installed\n * notifications: log directly for valid checksums\n * notifications: log directly when using download backends\n * chore: avoid trailing whitespace in error message\n * refactor: Switch logging to anstyle\n * refactor: Remove unused ColorableTerminal::carriage_return\n * notifications: privatize Notification type\n * notifications: log directly on creating temp files\n * notifications: log directly on temp root creation\n * notifications: log directly on file deletions\n * notifications: log directly on directory deletions\n * notifications: log directly about non-fatal errors\n * notifications: log directly about rolling back changes\n * notifications: log directly for retrying renames\n * notifications: log directly when removing directories\n * notifications: log directly when copying directories\n * notifications: log directly when linking directories\n * notifications: log directly when path canonicalization fails\n * notifications: log directly when creating directories\n * tests: use DistContext for dist::components tests\n * tests: move DistContext into library\n * tests: deduplicate distribution installation tests\n * notifications: tweak style\n * Inline utils Notification variants into top-level Notification\n * Inline dist Notification variants into top-level Notification\n * Inline dist::temp::Notification variants into top-level Notification\n * dist: remove temp::Notification variant from dist::Notification\n * dist: extract URL alteration from download() method\n * dist: detach download_component() from Manifestation\n * dist: introduce ComponentBinary type\n * dist: avoid passing through arguments\n * dist: avoid unnecessary type annotations\n * dist: avoid cloning components Vec\n * refactor: remove redundant references\n * dist: simpify casting to trait object\n * dist: deduplicate decompression setup code\n * cli: move more self update logic into self_update module\n * refactor(dist/manifestation): remove redundant `.to_string()`\n * Remove unneeded paranthesees\n * Fix link in the bug reporting template\n * ci(all-features/windows): update `OPENSSL_LIB_DIR` for OpenSSL v3 compatibility\n * docs(dev-guide): improve suggestion for overriding arg0\n * docs(dev-guide): mention the arg0 override trick on welcome page\n * docs(README): link CI status badge to GitHub Actions panel\n * feat(dist/manifestation): adjust default concurrent downloads when installing toolchains\n * feat(cli/rustup-mode): check updates for all channels unless `RUSTUP_CONCURRENT_DOWNLOADS` is set to 1\n * refactor: rename `num_channels` to `concurrent_downloads`\n * fix: fix hang by preventing `stream.buffered(0)` in concurrent downloads\n * test(dist/manifestation): extract `TestContext::*with_env()`\n * refactor(download): use `NonZero` instead of `NonZeroU64`\n * refactor(process): remove redundant `.context()` in `Process::concurrent_downloads()`\n * chore(deps/renovate): group version bumps for `windows-rs` crates\n * Upgrade windows crates\n * fix(cli/rustup_mode): use ASCII-compatible spinner\n * chore(deps): update aws-actions/configure-aws-credentials action to v5\n * feat(install): warn if default linker (cc) is missing; add respective test case\n * Remove hardcoded dependency to the master branch\n * feat(downloads): delay the reappearance of the progress bar when retrying a download\n * fix(downloads): correct faulty behavior when a download fails\n * fix(downloads): correct faulty output when retrying a download\n * feat(self_update): add tcsh shell support to cli #3413\n * Replace non_empty_env_var() with Process::var_opt()\n * fix(downloads): report real elapsed time of a component downloads instead of cumulative\n * Treat empty environment variables as unset\n * fix(downloads): honor the RUSTUP_CONCURRENT_DOWNLOADS by always having \"n\" concurrent downloads\n * chore(deps): disable default features for zstd\n * feat(downloads): introduce `RUSTUP_CONCURRENT_DOWNLOADS` to control concurrency\n * ci(check): make installation of `taplo-cli` faster\n * fix(notifications): delete unnecessary Download(Pop/Push)Unit notifications\n * fix(downloads): extract closure for downloading a component into a separate function\n * feat(downloads): concurrently download components\n * fix(downloads): add a comment to justify the unwrap on `.get()` of `OnceLock`\n * chore(deps): update actions/checkout action to v5\n * fix(download_timeout): introduce RUSTUP_DOWNLOAD_TIMEOUT for overriding download timeout\n * fix(downloads): substitute the LazyLock for a OnceLock\n * feat(rustup_mode): revise help message\n * feat: improve error message for `rustup which`\n * test: detach snapshots from component installation order\n * feat(download_tracker): refactor in favor of `indicatif`\n * feat(process): create a `ProgressDrawTarget` (for `indicatif`) inside the `Process`\n * fix(rustup-init/sh): avoid `hw.optional.*: 1` stdout in macOS arch check\n * hack(cli/common): suppress host emulation warnings in rustup's own CI\n * fix(test/clitools): pass `RUSTUP_CI` to in-process tests\n * ci(macos): run x64 workflows with Rosetta 2\n * docs(user-guide/environment-variables): clarify the unit of `RUSTUP_UNPACK_RAM`\n * docs(user-guide/environment-variables): unify description style\n * docs(user-guide/environment-variables): update description of `RUSTUP_IO_THREADS`\n * Limit Tokio worker threads to I/O thread count\n * Use manual Tokio runtime setup\n * Attach io_thread_count() to Process\n * Always consider RUSTUP_IO_THREADS as input for thread count\n * utils: express io_thread_count() in a simpler way\n * opt(err): show renaming file error source\n * Set a maximum thread limit for remove_dir_all\n * fix(toolchain/distributable): refine handling of known targets with no prebuilt artifacts\n * fix(ci/fetch-rust-docker): update comments\n * fix(ci/docker): update `CC` name for `powerpc64le-unknown-linux-gnu`\n * Extract self_update() from update_all_channels()\n * Show channel updates even if self update is not permitted\n * Remove Cargo feature indirection\n * Move Cfg::get_self_update_mode() to SelfUpdateMode::from_cfg()\n * Replace trivial enum with bool\n * feat(updates): introduce `RUSTUP_TERM_WIDTH` to override terminal width\n * feat(updates): introduce `RUSTUP_TERM_PROGRESS_WHEN` to toggle the progress bars\n * Limit the default number of I/O threads\n * Bump `toml` to 0.9\n * feat(updates): check for updates concurrently\n * feat(terminal): implement the `TermLike` trait for `ColorableTerminal`\n * chore: use match ergonomics in favor of explicit `ref`s\n * refactor(download/curl): use early returns in `download()`\n * chore(cli/rustup_mode): merge `std` imports\n * chore(cli/rustup-mode): import `std::io`\n * chore: fix new `clippy` warnings\n * fix(ci/run): specify target triple for `bindgen-cli` installation\n * feat(www): improve \"copy\" button style compatibility with Chromium\n * ci(run): install `codegen-cli` with `cargo-binstall`\n * docs: replace Discord links\n * Block broken snap curl\n * Upgrade to windows-sys 0.60\n * Emphasize that `llvm-tools` dist component is not subject to compiler stability guarantees\n * docs(README): update CI status badge\n * Fix rustup-init.sh cputype check for sparcv9\n * add Solaris support\n * test(clitools)!: remove all deprecated `.expect_*()` APIs\n * test(clitools)!: privatize `Config::run()`\n * test: migrate remaining uses of `.run()` to `.expect()` APIs\n * test(clitools): extract `Assert::redact()`\n * test: simplify `.display().to_string()` in `.extend_redactions()`\n * test(cli_misc): bring back missing assertions\n * Update help.rs: bash completions instructions (#1)\n * docs(user-guide): fix typo\n * docs(dev-guide): update the section on `clippy` lints\n * docs(dev-guide): mention test helpers and `Assert`\n * docs(test/clitools): add docs for `Assert`\n * Upgrade to rustls-platform-verifier 0.6\n * test(cli-v2): migrate to `.expect()` APIs\n * test(cli-misc): migrate to `.expect()` APIs\n * fix(toolchain): fix proxy fallback notification format on Windows\n * test(cli-v1): migrate to `.expect()` APIs\n * test(download): serialize tests with proxy-sensitive URLs\n * test(cli-rustup): migrate to `.expect()` APIs\n * test(clitool): add `Assert::remove_redactions()`\n * test(clitools): allow `OsStr`-like args in `Config::expect*()`\n * Fix CI image names for downloading ARM and PowerPC artifacts\n * Update platforms to 3.6\n * test(cli-exact): migrate to `.expect()` APIs\n * Avoid swallowing errors in show()\n * Simplify target processing logic\n * Inline returned bindings\n * Increase Windows main thread stack size to 2mb\n * test(cli-inst-interactive): migrate to `.expect()` APIs\n * Unset RUSTUP_AUTO_INSTALL for tests\n * test(cli-paths): migrate to `.expect()` APIs\n * test(cli-exact): use the new `[CURRENT_VERSION]` redaction\n * test(cli-self-upd): migrate to `.expect()` APIs\n * Tweak list_items() docstring\n * Leverage bool::then_some() to simplify some code\n * Avoid intermediate allocation in listing\n * test(custom-toolchains): `target list` now can display the installed targets\n * feat(custom-toolchains): `target` and `component list` working on custom toolchains\n * Skip manifest loading if there are no components/targets to check\n * fix(deps): update rust crate opener to 0.8.0\n * rustup check: set exit status based on available updates\n * rustup check: adopt no-self-update logic\n * feat(self_update): add proxy sanity checks\n * style(test): qualify uses of `snapbox::str![]`\n * refactor(test): migrate some tests to `.expect()` APIs\n * chore(test): deprecated old APIs overlapping with the new ones\n * refactor(test): add new `.expect()`-based testing APIs\n * test(custom-toolchains): using `show` on a custom toolchain without a `components` file\n * test(custom-toolchains): add test to showcase that the issue was solved\n * feat(custom-toolchains): `rustup show` now reporting installed targets\n * tests: print diffs on test failures\n * Log versions during self updates\n * Fix cargo lints on Windows\n * toolchain: hoist binary name conditionals out of fallback functions\n * refactor(test): replace `TempDir::into_path()` with `TempDir::keep()`\n * refactor(test/clitools): use globally-defined `tempdir_in_with_prefix()`\n * feat(toolchain): notify the user when proxy fallback is activated\n * feat(toolchain): consider external `rust-analyzer` when calling a proxy\n * refactor(toolchain): move predicates into `Toolchain::maybe_do_cargo_fallback()`\n * refactor(toolchain): privatize `Toolchain::maybe_do_cargo_fallback()`\n * deps: update aws-lc-rs to 1.13.1\n * docs(changelog): mirror changes from the release announcement, take 2\n * Deprecate native-tls as well\n * Enable HTTP/2 support for reqwest download backend\n * Emit tracing events from log facade calls\n * download: show Debug representation for errors\n * Avoid repeated globals in tracing events\n * Log original download errors immediately\n * feat(cli/rustup-mode): add aliases to `rustup component remove`\n * Switch flate2 to use the zlib-rs backend\n * Hardlink proxies if symlinks aren't reachable\n * Add powerpc64le-unknown-linux-musl support\n * Add toolchain_name to not installed bail msg\n * Warn about using curl\n * Drop workspace indirection\n * Fold download crate back into rustup\n * download: merge integration test files\n * Test CARGO environment replacement\n * Update CARGO env var if it is a rustup proxy\n * Tweak toolchain subcommand help text\n * Move toolchain and default commands first\n * show toolchain paths in rustup show -v output\n * refactor(cli/self-update): save allocations in `Nu::rcfiles()`\n * fix(cli/self-update)!: stop appending to `env.nu` due to deprecation\n * fix(cli/self-update): consider Windows paths in Nushell suggestions\n * refactor(cli/self-update): use `path add` in `env.nu` template\n * fix(cli/self-update): use interpolated string in `env.nu` template\n * Upgrade dependencies\n * docs(user-guide/environment-variables): document `RUSTUP_VERSION`\n * feat(rustup-init/sh): allow setting `RUSTUP_VERSION` during installation\n * feat(cli/self-update): allow setting `RUSTUP_VERSION` for arbitrary\n downgrades\n * feat(test/clitools): add `Config::expect_ok_ex_env()`\n * fix(errors)!: improve error messages for `RustupError::ToolchainNotInstalled`\n * Add set auto-install disable\n * Use `cursor: pointer` for copy button on website\n * fix(dist): refine suggestions about missing targets\n * Append Windows bin directory to PATH by default\n * Remove validation for custom toolchains when reading rust-toolchain.toml\n * document RUSTUP_AUTO_INSTALL\n * Fix build script `cargo` instructions\n","modified":"2026-10-03T17:00:03.791677441Z","published":"2026-10-02T19:31:21Z","related":["CVE-2024-12224","CVE-2025-58160","CVE-2026-25541","CVE-2026-25727","CVE-2026-41676","CVE-2026-41677","CVE-2026-41678","CVE-2026-41681","CVE-2026-41898","CVE-2026-42327","CVE-2026-44662","CVE-2026-45784","CVE-2026-93599","CVE-2026-93600","CVE-2026-93601","CVE-2026-93602"],"upstream":["CVE-2024-12224","CVE-2025-58160","CVE-2026-25541","CVE-2026-25727","CVE-2026-41676","CVE-2026-41677","CVE-2026-41678","CVE-2026-41681","CVE-2026-41898","CVE-2026-42327","CVE-2026-44662","CVE-2026-45784","CVE-2026-93599","CVE-2026-93600","CVE-2026-93601","CVE-2026-93602"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230032"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243862"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249008"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257902"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270186"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270521"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270619"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270644"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270795"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270870"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270874"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270989"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274144"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-12224"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58160"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25727"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41898"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45784"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93599"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93601"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93602"}],"affected":[{"package":{"name":"rustup","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/rustup&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.29.1~0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"rustup":"1.29.1~0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:22016-1.json"}}],"schema_version":"1.9.0"}