#1149888 rust-gix-fs: CVE-2026-100419

Package:
src:rust-gix-fs
Source:
src:rust-gix-fs
Submitter:
Salvatore Bonaccorso
Date:
2026-10-03 21:51:04 UTC
Severity:
normal
Tags:
#1149888#5
Date:
2026-10-03 21:50:07 UTC
From:
To:
Hi,

The following vulnerability was published for rust-gix-fs.

CVE-2026-100419[0]:
| gitoxide gix-fs before 0.23.0 contains a path validation bypass
| vulnerability in the worktree checkout mechanism that allows
| attackers to escape the worktree directory via symlink manipulation.
| During forced checkout with overwrite_existing enabled, attackers
| can craft malicious repository trees where symlink entries replace
| validated directories, causing subsequent files to be written
| outside the worktree through the symlink for code execution or file
| manipulation.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-100419
https://www.cve.org/CVERecord?id=CVE-2026-100419
[1] https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5
[2] https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore