vulnerability

FreeBSD: VID-ee26f513-826e-11ec-8be6-d4c9ef517024 (CVE-2022-21658): Rust -- Race condition enabling symlink following

Severity
3
CVSS
(AV:L/AC:M/Au:N/C:N/I:P/A:P)
Published
Jan 31, 2022
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

The Rust Security Response WG was notified that the std::fs::remove_dir_all standard library function is vulnerable to a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn't otherwise access or delete.

Solutions

freebsd-upgrade-package-rustfreebsd-upgrade-package-rust-nightly
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.