#1128404 rust-time: last upstream fixes a security issue impacting trixie

Package:
rust-time
Source:
rust-time
Submitter:
Yann Dirson
Date:
2026-05-26 20:35:02 UTC
Severity:
normal
Tags:
#1128404#5
Date:
2026-02-19 11:12:03 UTC
From:
To:
Upstream changelog[1] for 0.3.47 include a Security issue.
This can be tracked to commit 1c63dc7985b8fa26bd8c689423cc56b7a03841ee.
All lines modified by this commit were introduced in commit
e44875d26490edecaf6cdd5dfacc310916c76adb, included in 0.3.6, so I
believe 0.3.37 to be impacted.

It is the only security issue currently mentioned post-0.3.37 in their
changelog.


[1] https://github.com/time-rs/time/blob/main/CHANGELOG.md

#1128404#10
Date:
2026-02-19 11:20:06 UTC
From:
To:
This vuln is tracked as https://rustsec.org/advisories/RUSTSEC-2026-0009.html
#1128404#15
Date:
2026-02-19 14:09:35 UTC
From:
To:
fixed 1128404 0.3.47-1
thanks

#1128404#22
Date:
2026-05-26 13:00:25 UTC
From:
To:

#1128404#27
Date:
2026-05-26 20:32:08 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
rust-time, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1128404@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Bastian Germann <bage@debian.org> (supplier of updated rust-time package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 24 Feb 2026 17:00:26 +0100
Source: rust-time
Architecture: source
Version: 0.3.37-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net>
Changed-By: Bastian Germann <bage@debian.org>
Closes: 1128404
Changes:
 rust-time (0.3.37-1+deb13u1) trixie; urgency=medium
 .
   * Backport upstream fix for CVE-2026-25727 (Closes: #1128404)
Checksums-Sha1:
 2e7d8f4956dd0fdde422ede2ed64a11d7a073532 2598 rust-time_0.3.37-1+deb13u1.dsc
 e521dba278bbdf51b17f63dcd410f6694e9b5e8e 5640 rust-time_0.3.37-1+deb13u1.debian.tar.xz
 2159a1524e7edb80bfb75e7d9db696202287a208 10312 rust-time_0.3.37-1+deb13u1_source.buildinfo
Checksums-Sha256:
 63fab8846146872bc730b6b4760f09b420924675f73ff47eb6c8603c8103e9ee 2598 rust-time_0.3.37-1+deb13u1.dsc
 4791946e5349fc0068d04d02090d7743ad092a36e13cbaaeeff4380d137091a9 5640 rust-time_0.3.37-1+deb13u1.debian.tar.xz
 e67b8eb08a2b7e1b3a40da81860a07512a9718d2b505d2160d1fcf0c3f5eb78e 10312 rust-time_0.3.37-1+deb13u1_source.buildinfo
Files:
 c3fbc1505b7aba0234b836d8aa9012b2 2598 rust optional rust-time_0.3.37-1+deb13u1.dsc
 abdeb557f75cb8a6fecff7b52a669b4d 5640 rust optional rust-time_0.3.37-1+deb13u1.debian.tar.xz
 c5b1aed07fc3c4efa3142e64cab63917 10312 rust optional rust-time_0.3.37-1+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmoUtCQQHGJhZ2VAZGVi
aWFuLm9yZwAKCRAfXHqLRVZDFHOtDACxK89w4mCXAzL7hwhV8KN0GWh6cWTGIMLW
miBEuuwhvklz4oazTvL2twcuVIwGPOFGkNB8sJ8mjKeXau8UpL06UQsRGWxIb6pN
97cFqd1chfF+OpawWGo8LYpgnlNOn+G5ETne51UdnOb+EE69rbRvcFqivAbwo0f/
yhqkKiiUZxnlA48NLGa+LTNLpWSMbDycGiiWE25YXM5Lb+iByz6czPkM9wmBihQP
/z9nAiERP8n/llbcRsVQQYmVL9hMi3GTvErXybUcFZ51/WNLR4BW8gV/N6UjovMQ
UOY+wZ9NRqmBo2nCsfSsEAOwWwxv8iaiKpRb4gZKg5vICWc3ocuTlfhX4UCzHd9w
AkP6lhvoFTTgWdfGCMEVYg7VwejAF3zFwRFMRvkNRQns4IBA7zkByTQohaXFwUy+
o+G6FzuJlUkfIzGa97uejkf6Tns9wW4TLecGCujqgRUQoe21ubG4SJlQtiYoDgj/
on4rWoNqWcOcn1pBYIQKE1+hMFAqdYQ=
=kWUw
-----END PGP SIGNATURE-----

#1128404#32
Date:
2026-05-26 20:32:24 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
rust-time, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1128404@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Bastian Germann <bage@debian.org> (supplier of updated rust-time package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 24 Feb 2026 17:00:26 +0100
Source: rust-time
Architecture: source
Version: 0.3.9-1+deb12u1
Distribution: bookworm
Urgency: medium
Maintainer: Debian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net>
Changed-By: Bastian Germann <bage@debian.org>
Closes: 1128404
Changes:
 rust-time (0.3.9-1+deb12u1) bookworm; urgency=medium
 .
   * Backport upstream fix for CVE-2026-25727 (Closes: #1128404)
Checksums-Sha1:
 2203dd29ddfc0f4deb4c9ac2c860dbdf2a7e3a02 2241 rust-time_0.3.9-1+deb12u1.dsc
 025b68a53b611dfd94d996ceda3b4d5e72363059 5388 rust-time_0.3.9-1+deb12u1.debian.tar.xz
 20f0d887819d25d6f5163ddceefd8030bccf3fca 6956 rust-time_0.3.9-1+deb12u1_source.buildinfo
Checksums-Sha256:
 ab989dd56fa398c2fad98e83f59bf7df547609ddb473deb36aecc03790a5f0e8 2241 rust-time_0.3.9-1+deb12u1.dsc
 fdc4226300a5769c647d051e46bf96d15e0c3f1f33b634e031e6d1d70d9be417 5388 rust-time_0.3.9-1+deb12u1.debian.tar.xz
 7b0b8a1a0c03886770646a02dacad9f474301654c65a7a922b7749ff719b6dd2 6956 rust-time_0.3.9-1+deb12u1_source.buildinfo
Files:
 c01e07c221d242d7ce8127a327379647 2241 rust optional rust-time_0.3.9-1+deb12u1.dsc
 1fbbf0f45f6549b2c0e0eff7fcac74cc 5388 rust optional rust-time_0.3.9-1+deb12u1.debian.tar.xz
 20ae25dde0a2eb33a777b6eae7452011 6956 rust optional rust-time_0.3.9-1+deb12u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmoUtL4QHGJhZ2VAZGVi
aWFuLm9yZwAKCRAfXHqLRVZDFEXkDADaYnbizGXEptaZuZiFmCaa1YEcq9Gr2Ttp
2MMkeCOlRxVCRZjhQBsfr62ngxyy/vuAOGHTdxjn4vQN8kovb0bVos328CuWRxFn
Weo3XYEZsY+GeKgKqkFq4O9b+faHIlgelkDU3orio2v81FNKRB6KmCu69o3KT2pe
Ugeyp50LC0ch7Z4gVduBUrcjJCQPccF3raPGTL/VHQy6VXcnnaodPqfsZ8YfcOMS
U2kAUf0nklSXm4hMDIX0rU/rBGj4S9SDfGOrOcTZt7pL7sueJvgZnpwYB7TVOj1r
SMoKHmoUvgHQSuaWNfRBrPMvFQz2CZfbgnL85r1iEEGwNxxyD5TtwXwG0SAEH4s5
mnfrVahJ94ziNeAK9f08UIWvxjEG70sW6rJ4GokBXl5vLG1e2uBUBHjXJkyhqI+6
6A5qv1DaOETl5pAOeWE+l5Ng6jOLo/NA8HOI73+memAIoT7Bw5H3gBmbO5RC9TZx
UQg426bG4SyrBCkxTcDA2YQ8NO/vY5w=
=XwXC
-----END PGP SIGNATURE-----