openSUSE 16 Security Update : rustup (openSUSE-SU-2026:22016-1)

critical Nessus Plugin ID 362898

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has a package installed that is affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:22016-1 advisory.

- CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243862).
- CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249008).
- CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (bsc#1274144).
- CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257902).
- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270186).
- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270619).
- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270644).
- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270795).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270870).
- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270521).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust- openssl crate (bsc#1270874).
- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270989).
- CVE-2026-93599: rustls-webpki: panic via empty BIT STRING (bsc#1282217).
- CVE-2026-93600: rustls-webpki: name constraints URI validation bypass (bsc#1282217).
- CVE-2026-93601: rustls-webpki: name constraint bypass (bsc#1282217).
- CVE-2026-93602: rustls-webpki: CRL revocation check bypass (bsc#1282217).
- rust-shlex: Multiple issues involving quote API (RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032).

Changes for rustup:

- Update to version 1.29.1~0:
* dist(rustup-init/sh): update commit shasum in help string
* style(bin/rustup-init): reformat code
* docs(changelog): update for v1.29.1 stable release
* warn how to switch away from the deprecated complete profile
* fix(cli/help): fix wording in `rustup run --help`
* ci(docker/android): stop building OpenSSL
* refactor(cli/docs): use tracing for docs opening status messages
* refactor(self-update): rename Windows uninstall registry helpers
* feat(test): isolate Windows registry state per test
* docs(dev-guide): mention how to support new compilation targets
* Fix funding link
* chore(deps): lock file maintenance
* refactor(cli/self-update): move `current_install_opts()` to `InstallOpts::display()`
* refactor(cli/self-update): move `process` out of `InstallOpts`
* fix(cli/self-update): postpone initialization of `Cfg` in `setup_mode`
* refactor(cli/self-update): take `Process` in `check_existence_of_settings_file()`
* fix(settings): prevent creating new file with `SettingsFile::read_settings()`
* test(cli-inst-interactive): test file creation on cancelled installation
* refactor(toolchain/names): inline `validate()` aliases into `FromStr`
* refactor(toolchain/names): rename `validate()` to `normalize_name()`
* fix minor typos
* www: align copy icon
* refactor(toolchain/names)!: remove `try_from_str!()`
* refactor(toolchain/names)!: remove `from_variant!()`
* Add `rustup doc --serve` to serve docs over local HTTP
* Move doc() and man() into a new docs module
* chore(github): comment out instructions in PR template
* docs(dev-guide): reapply abandoned changes from #4970
* Add riscv64 unknown linux musl support
* fix(deps): update rust crate enum-map to v3
* refactor(cli/self-update)!: rename `install()` to `InstallOpts::install()`
* refactor(cli/self-update)!: rename `maybe_install_rust()` to `InstallOpts::install_rust()`
* refactor(cli/self-update)!: rename `InstallOpts::install()` to `InstallOpts::select_toolchain()`
* refactor(toolchain/names)!: make more clones during conversions explicit
* refactor(cli/self-update): move message templates to `mod msg`
* style(cli/self-update): reorganize imports
* Add pull request template linking to the dev guide
* doc: add AI policy to the dev guide
* ci(dist): ensure pushing to `dev-static` on `stable` update
* test(toolchain): add a test case for `rustup toolchain install --override`
* feat(toolchain): add `--default` flag to `rustup toolchain install`
* fix(toolchain): inline use of `set_override`
* Add Enzyme to the list of rustup components
* fix: repair toolchains without an installed manifest
* refactor: expose the installed manifest path
* Docs: Remove i686 `set default-host` example
* fix(self-update): only remove complete profile lines
* chore(deps): bump `platforms` to 4.1.0
* chore(deps): remove pinned `openssl-src`
* refactor: replace `cfg_if!{}` with `cfg_select!{}`
* fix: Lock state file updates
* Fix Rust 1.97 clippy warnings
* uninstalls toolchains prior to deleting the rustup home folder
* Take semver-compatible dependency updates
* Upgrade platforms to 4
* docs: update `CHANGELOG` for v1.29.1
* Lock file maintenance
* Remove Windows special case from `can_run`
* diskio: drop unnecessary constructor wrapper
* diskio: rename _IncrementalFileState to FileState
* diskio: inline IncrementalFileState type alias
* Minimize API visibility
* toolchain: streamline validate() implementations
* toolchain: avoid internal cloning
* dist: drop unused conversion impl
* dist: keep impls with type definitions
* Don't hide allocations inside From impls
* toolchain: drop impls for &String
* Warn on clippy::or_fun_call
* Warn on clippy::needless_by_ref_mut
* Warn on clippy::redundant_clone
* Warn on clippy::manual_let_else
* Warn on clippy::use_self
* errors: box ToolchainDesc in RustupError variants
* errors: box Manifest in RequestedComponentsUnavailable variant
* No (more) need to allow clippy::arc_with_non_send_sync
* Replace use of FnMut trait objects with custom trait
* test(cli/self-upd): use direct arg0 override for `as_rustup_setup()`
* chore(deps): update actions/cache action to v6
* ci(windows): add support for aarch64-pc-windows-gnullvm target
* ci(windows): refine MSVC/MINGW job step predicates
* chore(deps): update actions/checkout action to v7
* fix(deps): update rust crate itertools to 0.15
* fix(progress): use the `prefix` placeholder instead of `msg` for component name
* rustup: warn when no toolchain or default is configured
* errors: extract default stable hint
* feat(toolchain): make the installed text of a toolchain install green
* Add aarch64-unknown-freebsd
* chore: address linter warnings
* chore(deps): bump to semver-compatible versions
* Add funding links
* ci(docker/freebsd): bump `clang` version to `freebsd14`
* ci(freebsd): use FreeBSD 14.0 for full CI
* chore(deps): update `curl`
* feat(cli/rustup-mode): warn about auto-installation in some subcommands
* refactor(config): accept `Cfg` in `EnsureInstalled::warn_auto_install()`
* test(cli/rustup-mode): test auto-installation on to-be-deprecated subcommand
* dist: move display_name() before other methods that it calls
* chore(gitignore): add .cargo/config.windows-cross.toml to gitignore
* docs(dev-guide): update platform-specific code guidance
* docs(dev-guide): mention rust-analyzer support for Windows-specific code on Unix
* docs(dev-guide): mention how to lint Windows-specific code on Unix
* chore(config): add example config for cross checking and rust-analyzer
* chore: add rust-analyzer example config
* Display the full names of targets not matching the host target tuple
* docs(dev-guide/tips-and-tricks): mention the `RUSTUP_FORCE_ARG0='rustup'` cargo alias
* build(cargo): add `cargo` alias for `RUSTUP_FORCE_ARG0='rustup'`
* docs: rename the repath helper variable
* Remove double buffering when extracting archives
* refactor(toolchain/distributable): return `EnsureInstalled<>` from `DistributableToolchain::install()`
* docs(dev-guide/coding-standards): adapt style guide from rustls
* fix(deps): update opentelemetry
* feat(config): warn user if auto-install is enabled
* refactor(config): return `EnsureInstalled<>` from more functions
* refactor(config): extract `EnsureInstalled<>` wrapper type
* test: make tests agnostic to external `RUSTUP_AUTO_INSTALL` and `RUST_RECURSION_COUNT`
* test(dist): fail v2 manifest update when manifest disagrees with .sha256
* fix(dist): propagate v2 manifest checksum failure instead of reporting unchanged
* Align shell setup comments in install message
* feat(cli/self-update): refine wording of already installed Rust warning
* chore(settings): rename default_host_triple to default_host_tuple and alias old name
* chore(settings): add test to parse default_host_triple in toml
* test(download): also scrub `HTTP_PROXY` in `scrub_env()`
* chore: document legacy default host setting
* chore: rename internal tuple constants
* chore: rename partially Triple to Tuple to reflect the new terminology
* fix(cli/rustup-mode)!: complete `rustup show` if active toolchain is not installed
* refactor(cli/rustup-mode): postpone eval of `active_toolchain_targets` in `show()`
* refactor(cli/rustup-mode): postpone eval of `active_toolchain` in `show()`
* refactor(cli/rustup-mode): reduce rightward drift in `show()`
* refactor(cli/rustup-mode): refine usage of `stdout` term and locks in `show()`
* feat(config): add `Cfg` field to force-disable auto-installation
* Provide --yes alias for -y flag consistently
* refactor(tests): rename triple to tuple
* refactor: bulk rename triple to ruple
* refactor: rename get_default_host_triple to default_host_tuple
* test(download): support more feature flag combinations
* docs: fix the FileBuffer::clear doc comment wording
* docs: fix plural of VM in coding standards
* fix(dist): bulk rename triple to tuple for variables and messages
* refactor(dist): rename PartialTargetTriple to PartialTargetTuple
* refactor(dist): rename triple module to target_tuple
* refactor: remove PartialToochainDesc::has_triple() in favor to PartialTargetTriple::is_empty()
* refactor(dist): rename TargetTriple to TargetTuple
* fix(self-update): rename triple to tuple in self_update
* dist: bump `rustup` version to v1.29.1
* ci(linux/x64-musl): install missing libc dependencies
* fix(tests): rename HOST_TRIPLE placeholder to HOST_TUPLE
* fix(tests): rename this_host_triple() to this_host_tuple()
* fix(init): rename triple to tuple to reflect the new terminology
* fix(docs): rename triple to tuple to reflect the new terminology
* chore(deps): update ubuntu docker tag to v26
* Improve error message for incomplete toolchains
* chore(deps): update bwoodsend/setup-winlibs-action action to v1.16
* test(dist/manifest): use the reordered fixture in `manifest_serialized_with_sorted_keys`
* docs: fix initial spelling in stylesheet variable
* ci: powerpc64-unknown-linux-musl is now stable
* style(cli/rustup-mode): address clippy warnings
* docs(dev-guide): update release process with new backporting flow
* docs: fix actions template README typo
* Only show post-install instructions for currently installed shells
* docs: fix Windows MSVC guide typo
* Upgrade to rustls-platform-verifier 0.7
* Make component removal best-effort and preserve single-error behavior
* Use `cc-rs` to detect the default linker, instead of assuming `cc`
* ci(test): add `workflow_dispatch` trigger on par with `schedule`
* ci: fix incorrect `contains()` predicate
* fix(dist/manifestation): fix log format when installing exactly 2 components
* Allow rustup component add to install multiple components in one update #4787
* fix(docs): correct link to `no-self-update` feature
* ci: enable on all PR target branches
* ci(backport): rename backport branches to `release/*`
* feat(toolchain): run a pre-check before updating all toolchains
* feat(install): accept an optional pre-fetched manifest when installing
* fix(toolchain): extract manifest fetching out of `show_dist_version()`
* fix(manifest): aggregate a manifest and its hash in a `ManifestWithHash` struct
* fix: Reduce flickering by using `set_move_cursor`
* ci(backport): add support for backporting
* fix: install message misalignment.
* refactor: extracted `progress_style` method for DownloadStatus
* fix(deps): update rust crate sha2 to 0.11
* chore(doc): Added comments for clarify the usage of `Component::name` `Manifest::name` and the `short_name` funcc accordingly.
* refactor: Rename `Component`'s `name_in_manifest` to `name` and `short_name` accordingly
* self_update: show path to executable in case of updater failure
* Revert fix(ci/freebsd): install ca certs to prevent certificate-related issues
* ci: don't install protoc
* Update to mdbook 0.5
* ci(all-features): bump protoc version
* fix(dist/manifestation): use full toolchain name in `Update::unavailable_components()`
* style(dist/manifestation): merge imports
* Fix zsh completion showing all PATH entries for +toolchain arg
* fix(cli/proxy-mode): stop enforcing `quiet: true`
* chore(deps/freebsd): downgrade `libz-sys` to v1.1.24
* fix(ci/freebsd): install ca certs to prevent certificate-related issues
* fix(rustup-init/sh): prevent passing `--default-host` twice
* Avoid warning about the existence of a `settings.toml` on a fresh install
* use tuple instead of triple for env overrides
* Take platforms 3.9.0
* Unpin tracing-subcriber
* chore(deps): update `aws-lc-rs` and `aws-lc-sys`
* docs(changelog): update release date for v1.29.0
* docs(dev-guide/release-process): mention the CfT blog post
* docs(changelog): update for v1.29.0 stable release
* fix(cli): Style CLI errors in init mode
* test: Add unknown arg init test
* chore(deps): update actions/upload-artifact action to v7
* refactor(www): simplify instruction css selector
* feat(www): make copy button dark mode-aware
* feat(www): move feedback text out of copy button
* fix(www): apply filter to rust logo
* feat(www): add dark mode
* refactor(www): extract css variables
* fix(cli/self-update): enforce a newline after `check_updates()`
* refactor(cli/self-update): extract `has_progress_bars` in `check_updates()`
* fix(cli/self-update): unify `check_*update*()`'s message formats
* docs(downloads): fix the default number of `RUSTUP_CONCURRENT_DOWNLOADS`
* feat(toolchain): add `--override` to override toolchain as soon as installed
* fix(toolchain): improve logs when recovering from an interrupted installation
* chore(deps): downgrade `openssl-src` to 300.5.4+3.5.4
* style(download): clean up imports
* fix(diskio): fall back to single-threaded unpacking when `ram_budget` < 512MB to avoid OOM on memory- constrained systems
* test(downloads): check if an error is thrown if the server does not honor range
* fix(downloads): check correct response when resuming from partial (reqwest)
* fix(downloads): check correct response when resuming from partial (curl)
* fix(deps): update rust crate toml to v1
* fix(dist/manifest): sort keys when serializing `Manifest`
* hack(ci/linux): disable BuildKit when building local images
* chore(ci): use more distinctive local image names
* Upgrade rand to 0.10
* Upgrade snapbox to 1
* Upgrade to anstream 1
* fix(downloads): adjust error message for partial files in network failures
* test(downloads): ensure that partial files are not removed when network fails
* feat(downloads): do not delete partial download when network fails
* fix(downloads): substitute `DEK` alias for `DownloadError`
* chore(deps): update aws-actions/configure-aws-credentials action to v6
* cli: introduce semantic exit code constants for rustup check
* Add missing Windows SDK instructions
* Add winget instructions to MSVC install page
* Remove nu-string-interpolation `$`
* Replace $nu.home-path with ~
* feat(cli/rustup-mode): add Exit status section to `rustup check --help`
* Add common commands section in help text
* fix(cli/rustup-mode): improve exit code of `rustup check`
* refactor(test)!: pass status code directly to `SanitizedOutput`
* Add powerpc64-unknown-linux-musl support
* fix: add copy_file_symlink_to_source for self-installation
* fix: preserve symlinks in copy_dir instead of following them
* feat(cli/rustup-mode): add `doc --rustc-docs` to open rustdoc for Rust internals
* Remove the mixed singular/plural phrasing as component(s) instead, use components or component.
In the singular case also add the name of the component for more consistent messaging style with other info! outputs about single components.
* fix(cli/rustup-mode): `check` for self updates for `SelfUpdateMode::CheckOnly`
* test: Add test for sequential multi-toolchain uninstall
* fix: directory removal race condition in toolchain uninstall
* test(cli_v2): test error when missing many components on install
* fix(dist): adjust printed newlines in `components_missing_msg()`
* unified nightly disclaimer wording/styling; preserved distinct messages per scenario
* Upgrade to reqwest 0.13
* change test name to match new terminology
* rename file to match new terminology
* change 'target triple' to 'target tuple'
* fix(toolchain): forbid toolchain names starting with +
* cli: add `doc --releases` to open release notes
* chore(deps): update actions/upload-artifact action to v6
* chore(deps): update actions/cache action to v5
* dist: use more concise API in helper function
* dist: inline more logic into helper function
* dist: give helper function a more meaningful name
* dist: move helper function closer to usage site
* docs(dev-guide): mention snapshot updating in release process
* fix(toolchain): avoid unwrapping when parsing a toolchain name
* fix(toolchain): change regex to reject leading zeros in toolchain name
* docs(changelog): update for v1.29.0 beta release
* dist: bump `rustup` version to v1.29.0
* docs(changelog): add missing link references
* test(static-roots): use a more compact syntax for raw binaries
* test(static-roots): return `Result` from `store_static_roots()`
* download: statically bundle relevant trust anchors
* Added xonsh support
* refactor(dist/manifestation): remove redundant redeclarations
* docs(dist/download): remove outdated note on concurrent download progress reporting
* fix(dist/download): align `total_bytes` fields in progress reporting UI
* fix: default to GNU host in Cygwin/MSYS/MinGW environments (#4221)
* chore(config): remove redundant imports
* fix(dist/manifestation): print downloading component only on `InstallEvents`
* fix(utils): downgrade panic to warning in `delete_dir_contents_following_links()`
* chore(deps): update actions/checkout action to v6
* Prepare for mdbook 0.5 migration
* dist: make installation asynchronous
* dist: make installations 'static
* dist: take ownership of Manifestation
* dist: store owned temp::Context in Transaction
* dist: store temp::Context in DownloadCfg
* dist: align progress bar elements
* dist: track progress during unpacking
* utils: drop unused reader tracking
* process: fix refresh rate for progress bars
* process: reduce duplication in ProgressDrawTarget setup
* Yield references from Manifest::short_name()
* Move Component name helpers to Manifest
* dist: simplify ComponentBinary construction
* dist: hoist creation of io_executor some more
* Move unpack_ram() from dist to diskio
* dist: hoist Executor creation up
* dist: inline effective RAM limit calculation
* dist: hoist environment variable extraction
* dist: use logging for missing parent warnings
* dist: clarify dependency on unpack RAM budget
* diskio: clarify dependency on I/O thread count
* dist: transfer ownership of component values
* dist: take ownership of existing Components
* dist: take ownership of toolchain name in update()
* dist: take ownership of manifest in update()
* dist: derive trivial initialization for Update
* dist: rename Update::build_update() to new()
* dist: linearize for-loop in Update::build_update()
* dist: inline single-use function
* dist: inline trivial helper function
* dist: inline single-use tranaction change helpers
* dist: store specific config bit in Transaction
* chore(config): migrate config .github/renovate.json
* dist: attach manifest download functions to DownloadCfg
* rustup: unhide top-level install/uninstall commands
* dist: move update_from_dist() to DistOptions::install_into()
* Be more consistent about aliases for different subcommands
* test: add test for `rustup toolchain install --no-update`
* feat(rustup-mode): add `no_update` flag to `rustup toolchain install`
* cli: prepare DistOptions in advance
* dist: inline trivial wrapper function
* cli: inline single-use update_all_channels() helper
* config: simplify update_all_channels()
* dist: deduplicate DistOptions initialization
* dist: avoid recomputing dist root URL
* dist: simplify tracing instrumentation
* install: take ownership in InstallMethod::install()
* dist: move DistributableToolchain::install() up
* dist: clarify when update_hash is available
* cli: avoid dropped temporary
* Take semver-compatible dependencies
* dist: install while downloading
* dist: store more context in ComponentBinary
* dist: yield self when download is complete
* dist: move URL alteration logic into DownloadCfg method
* Apply suggestions from clippy 1.91
* refactor(check): Consolidate use_colors checks
* fix(check): Use Cargo's colors
* refactor(check): Make calls more consistent
* dist: drop another layer of abstraction
* dist: store package directory once
* dist: inline short single-use function
* dist: discard unnecessary abstraction layer
* chore(deps): update actions/upload-artifact action to v5
* fix(cli/rustup-mode): add missing self-update in `rustup toolchain install`
* refactor(cli/self-update): move `self_update()` to `SelfUpdateMode::update()`
* refactor(cli/rustup-mode): pass self-update predicates into `self_update()`
* refactor(cli/self-update): import `utils::ExitCode`
* rustup: tweak update check output style
* fix(list): Match show command's styling
* test(list): Add UI test
* fix(toolchain): Have 'list' match 'show's styling
* refactor(toolchain): Order logic by display order
* refactor(toolchain): Use string interpolation
* test(toolchain): Show list's behavior
* fix(update): Match 'cargo update's colors
* refactor(update): Centralize style knowledge
* test: Cover different show_channel_update cases
* fix(check): Subject check to RUSTUP_TERM_COLOR
* test(check): Show current style
* fix: Use HEADER styling in 'rustup show'
* chore: Update clap-cargo
* test: Demonstrate show's behavior
* test(process): Allow forcing color on
* test(process): Ensure non-locked writes are stripped of ANSI escape codes
* cli: update `uninstall_removes_source_from_rcs` to mirror `uninstall_doesnt_modify_rcs_with_no_modify_path`
* cli: add tests for `rustup self uninstall --no-modify-path`
* cli: add `rustup self uninstall --no-modify-path`
* cli: add help text for `rustup self uninstall -y`
* fix(cli/help): change indentation of discussions to 2 spaces
* fix(cli/help): adjust help text for `rustup install`
* feat(cli/help): add toolchain install tips to `rustup update`'s discussion
* feat(cli/help): discuss `rustup toolchain install`
* style: Remove wildcard imports
* progress: modify progress bar's states to be column-aligned
* installations: handle installation of components through progress bars
* feat(cli): Add a sub-heading style for 'completion' Help Discussion
* feat(cli): Have Help Discussions match rest of CLI Help
* feat(cli): Add color to clap help/errors
* refactor(cli): Switch help text to functions
* cli: propagate ActiveSource from the top
* cli: upgrade error events to ERROR level
* cli: inline Cfg::active_rustc_version()
* cli: extract display_version() from rustup main()
* cli: inline Cfg::resolve_local_toolchain()
* cli: inline Cfg::resolve_toolchain()
* config: extract setting of toolchain override in rustup help mode
* cli: avoid Cfg construction indirection
* config: privatize some Cfg fields
* config: drop trivial Cfg setters
* Expand `RUSTUP_TOOLCHAIN_SOURCE`'s documentation
* refactor(installation): extract installation of a component into a separate function
* bin: clean up imports
* cli: rename CLIError to CliError
* config: rename OverrideDB to OverrideDb
* dist: clean up unnecessary qualification
* test: Replace trycmd with snapbox
* chore: Update snapbox
* Update the default Windows SDK version
* refactor(log): Single source RUSTUP_TERM_COLOR
* style: Encourage using existing imports
* process: avoid fine-grained locking for logs
* process: discard unnecessary layer of synchronization
* process: inline TerminalInnerLocked
* process: replace unsafe code with safe equivalent
* process: extract color_choice() method
* process: extract is_a_tty value
* process: inline StreamSelector::is_a_tty()
* process: inline TestWriterLock
* Implement `RUSTUP_TOOLCHAIN_SOURCE` with new `Display` impl
* Move `Display` impl to `to_reason()`
* Rename `ActiveReason` to `ActiveSource`
* dist: simplify DownloadStatus setup
* dist: decentralize download status
* dist: postpone creation of ComponentBinary values
* dist: extract DownloadStatus type
* dist: call DownloadTracker methods directly
* dist: drop unnecessary Notifier layer
* dist: replace PackageContext with DownloadCfg
* refactor: Directly apply styling
* refactor: Don't bother grabbing lock for tests
* refactor: Replace termcolor with anstream
* refactor: Move style building out of ColorableTerminal
* refactor: Migrate to anstyle for color definitions
* fix(www): removes www subdomain from all rust-lang.org urls
* dist: move Notification into dist::download
* notifications: remove unused Display impl
* dist: move Notifier into DownloadCfg
* cli: build ...

Please note that the description has been truncated due to length. Please refer to vendor advisory for the full description.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected rustup package.

See Also

https://bugzilla.suse.com/1230032

https://bugzilla.suse.com/1243862

https://bugzilla.suse.com/1249008

https://bugzilla.suse.com/1257902

https://bugzilla.suse.com/1270186

https://bugzilla.suse.com/1270521

https://bugzilla.suse.com/1270619

https://bugzilla.suse.com/1270644

https://bugzilla.suse.com/1270795

https://bugzilla.suse.com/1270870

https://bugzilla.suse.com/1270874

https://bugzilla.suse.com/1270989

https://bugzilla.suse.com/1274144

https://bugzilla.suse.com/1282217

https://www.suse.com/security/cve/CVE-2024-12224

https://www.suse.com/security/cve/CVE-2025-58160

https://www.suse.com/security/cve/CVE-2026-25541

https://www.suse.com/security/cve/CVE-2026-25727

https://www.suse.com/security/cve/CVE-2026-41676

https://www.suse.com/security/cve/CVE-2026-41677

https://www.suse.com/security/cve/CVE-2026-41678

https://www.suse.com/security/cve/CVE-2026-41681

https://www.suse.com/security/cve/CVE-2026-41898

https://www.suse.com/security/cve/CVE-2026-42327

https://www.suse.com/security/cve/CVE-2026-44662

https://www.suse.com/security/cve/CVE-2026-45784

https://www.suse.com/security/cve/CVE-2026-93599

https://www.suse.com/security/cve/CVE-2026-93600

https://www.suse.com/security/cve/CVE-2026-93601

https://www.suse.com/security/cve/CVE-2026-93602

Plugin Details

Severity: Critical

ID: 362898

File Name: openSUSE-2026-22016-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/4/2026

Updated: 10/4/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-12224

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-41677

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-41681

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:rustup

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/2/2026

Vulnerability Publication Date: 12/9/2024

Reference Information

CVE: CVE-2024-12224, CVE-2025-58160, CVE-2026-25541, CVE-2026-25727, CVE-2026-41676, CVE-2026-41677, CVE-2026-41678, CVE-2026-41681, CVE-2026-41898, CVE-2026-42327, CVE-2026-44662, CVE-2026-45784, CVE-2026-93599, CVE-2026-93600, CVE-2026-93601, CVE-2026-93602