A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.
https://rustsec.org/advisories/RUSTSEC-2025-0040.html
https://github.com/ogham/rust-users/issues/44
https://crates.io/crates/users