{"id":"openSUSE-SU-2026:20060-1","summary":"Security update for cargo-c","details":"This update for cargo-c fixes the following issues:\n\n- CVE-2025-4574: crossbeam-channel: Fixed double-free on drop in Channel::discard_all_messages (bsc#1243179)\n- CVE-2025-58160: tracing-subscriber: Fixed log pollution (bsc#1249012)\n- CVE-2024-12224: idna: Fixed improper validation of Punycode labels (bsc#1243851)\n\nOther fixes:\n- Fixed _service file to have proper versioning\n- Update to version 0.10.15~git0.3e178d5:\n  * Bump actions/download-artifact from 4 to 5\n  * Update implib requirement from 0.3.5 to 0.4.0\n  * Add rlib to the targets when building tests\n  * Allow disabling emission of library version constants in header files\n  * Bump to cargo 0.90\n  * Fix static_libraries swallowing sequence of -framework flags\n  * Fix non-POSIX paths in Libdir under Windows\n  * Bump actions-rs-plus/clippy-check from 2.2.1 to 2.3.0\n  * Fix clippy lints\n  * Bump cargo-0.89, object-0.37.1, cbindgen-0.29\n","modified":"2026-03-12T02:08:04.642104Z","published":"2026-01-19T10:42:10Z","related":["CVE-2024-12224","CVE-2025-4574","CVE-2025-58160"],"upstream":["CVE-2024-12224","CVE-2025-4574","CVE-2025-58160"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243179"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243851"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249012"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-12224"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-4574"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58160"}],"affected":[{"package":{"name":"cargo-c","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/cargo-c&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.15-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"cargo-c":"0.10.15-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20060-1.json"}}],"schema_version":"1.7.5"}