Upstream changelog[1] for 0.3.47 include a Security issue. This can be tracked to commit 1c63dc7985b8fa26bd8c689423cc56b7a03841ee. All lines modified by this commit were introduced in commit e44875d26490edecaf6cdd5dfacc310916c76adb, included in 0.3.6, so I believe 0.3.37 to be impacted. It is the only security issue currently mentioned post-0.3.37 in their changelog. [1] https://github.com/time-rs/time/blob/main/CHANGELOG.md
This vuln is tracked as https://rustsec.org/advisories/RUSTSEC-2026-0009.html
fixed 1128404 0.3.47-1 thanks
We believe that the bug you reported is fixed in the latest version of rust-time, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1128404@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Bastian Germann <bage@debian.org> (supplier of updated rust-time package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Tue, 24 Feb 2026 17:00:26 +0100 Source: rust-time Architecture: source Version: 0.3.37-1+deb13u1 Distribution: trixie Urgency: medium Maintainer: Debian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net> Changed-By: Bastian Germann <bage@debian.org> Closes: 1128404 Changes: rust-time (0.3.37-1+deb13u1) trixie; urgency=medium . * Backport upstream fix for CVE-2026-25727 (Closes: #1128404) Checksums-Sha1: 2e7d8f4956dd0fdde422ede2ed64a11d7a073532 2598 rust-time_0.3.37-1+deb13u1.dsc e521dba278bbdf51b17f63dcd410f6694e9b5e8e 5640 rust-time_0.3.37-1+deb13u1.debian.tar.xz 2159a1524e7edb80bfb75e7d9db696202287a208 10312 rust-time_0.3.37-1+deb13u1_source.buildinfo Checksums-Sha256: 63fab8846146872bc730b6b4760f09b420924675f73ff47eb6c8603c8103e9ee 2598 rust-time_0.3.37-1+deb13u1.dsc 4791946e5349fc0068d04d02090d7743ad092a36e13cbaaeeff4380d137091a9 5640 rust-time_0.3.37-1+deb13u1.debian.tar.xz e67b8eb08a2b7e1b3a40da81860a07512a9718d2b505d2160d1fcf0c3f5eb78e 10312 rust-time_0.3.37-1+deb13u1_source.buildinfo Files: c3fbc1505b7aba0234b836d8aa9012b2 2598 rust optional rust-time_0.3.37-1+deb13u1.dsc abdeb557f75cb8a6fecff7b52a669b4d 5640 rust optional rust-time_0.3.37-1+deb13u1.debian.tar.xz c5b1aed07fc3c4efa3142e64cab63917 10312 rust optional rust-time_0.3.37-1+deb13u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmoUtCQQHGJhZ2VAZGVi aWFuLm9yZwAKCRAfXHqLRVZDFHOtDACxK89w4mCXAzL7hwhV8KN0GWh6cWTGIMLW miBEuuwhvklz4oazTvL2twcuVIwGPOFGkNB8sJ8mjKeXau8UpL06UQsRGWxIb6pN 97cFqd1chfF+OpawWGo8LYpgnlNOn+G5ETne51UdnOb+EE69rbRvcFqivAbwo0f/ yhqkKiiUZxnlA48NLGa+LTNLpWSMbDycGiiWE25YXM5Lb+iByz6czPkM9wmBihQP /z9nAiERP8n/llbcRsVQQYmVL9hMi3GTvErXybUcFZ51/WNLR4BW8gV/N6UjovMQ UOY+wZ9NRqmBo2nCsfSsEAOwWwxv8iaiKpRb4gZKg5vICWc3ocuTlfhX4UCzHd9w AkP6lhvoFTTgWdfGCMEVYg7VwejAF3zFwRFMRvkNRQns4IBA7zkByTQohaXFwUy+ o+G6FzuJlUkfIzGa97uejkf6Tns9wW4TLecGCujqgRUQoe21ubG4SJlQtiYoDgj/ on4rWoNqWcOcn1pBYIQKE1+hMFAqdYQ= =kWUw -----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of rust-time, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1128404@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Bastian Germann <bage@debian.org> (supplier of updated rust-time package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Tue, 24 Feb 2026 17:00:26 +0100 Source: rust-time Architecture: source Version: 0.3.9-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: Debian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net> Changed-By: Bastian Germann <bage@debian.org> Closes: 1128404 Changes: rust-time (0.3.9-1+deb12u1) bookworm; urgency=medium . * Backport upstream fix for CVE-2026-25727 (Closes: #1128404) Checksums-Sha1: 2203dd29ddfc0f4deb4c9ac2c860dbdf2a7e3a02 2241 rust-time_0.3.9-1+deb12u1.dsc 025b68a53b611dfd94d996ceda3b4d5e72363059 5388 rust-time_0.3.9-1+deb12u1.debian.tar.xz 20f0d887819d25d6f5163ddceefd8030bccf3fca 6956 rust-time_0.3.9-1+deb12u1_source.buildinfo Checksums-Sha256: ab989dd56fa398c2fad98e83f59bf7df547609ddb473deb36aecc03790a5f0e8 2241 rust-time_0.3.9-1+deb12u1.dsc fdc4226300a5769c647d051e46bf96d15e0c3f1f33b634e031e6d1d70d9be417 5388 rust-time_0.3.9-1+deb12u1.debian.tar.xz 7b0b8a1a0c03886770646a02dacad9f474301654c65a7a922b7749ff719b6dd2 6956 rust-time_0.3.9-1+deb12u1_source.buildinfo Files: c01e07c221d242d7ce8127a327379647 2241 rust optional rust-time_0.3.9-1+deb12u1.dsc 1fbbf0f45f6549b2c0e0eff7fcac74cc 5388 rust optional rust-time_0.3.9-1+deb12u1.debian.tar.xz 20ae25dde0a2eb33a777b6eae7452011 6956 rust optional rust-time_0.3.9-1+deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmoUtL4QHGJhZ2VAZGVi aWFuLm9yZwAKCRAfXHqLRVZDFEXkDADaYnbizGXEptaZuZiFmCaa1YEcq9Gr2Ttp 2MMkeCOlRxVCRZjhQBsfr62ngxyy/vuAOGHTdxjn4vQN8kovb0bVos328CuWRxFn Weo3XYEZsY+GeKgKqkFq4O9b+faHIlgelkDU3orio2v81FNKRB6KmCu69o3KT2pe Ugeyp50LC0ch7Z4gVduBUrcjJCQPccF3raPGTL/VHQy6VXcnnaodPqfsZ8YfcOMS U2kAUf0nklSXm4hMDIX0rU/rBGj4S9SDfGOrOcTZt7pL7sueJvgZnpwYB7TVOj1r SMoKHmoUvgHQSuaWNfRBrPMvFQz2CZfbgnL85r1iEEGwNxxyD5TtwXwG0SAEH4s5 mnfrVahJ94ziNeAK9f08UIWvxjEG70sW6rJ4GokBXl5vLG1e2uBUBHjXJkyhqI+6 6A5qv1DaOETl5pAOeWE+l5Ng6jOLo/NA8HOI73+memAIoT7Bw5H3gBmbO5RC9TZx UQg426bG4SyrBCkxTcDA2YQ8NO/vY5w= =XwXC -----END PGP SIGNATURE-----