A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could potentially result in application instability or other unforeseen consequences.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade rust-debugger-commonUpgrade rust-std-staticUpgrade rust-toolset-srpm-macrosUpgrade clippyUpgrade cargoUpgrade rust-docUpgrade rust-srcUpgrade rustUpgrade rust-analyzerUpgrade rust-gdbUpgrade rustfmtUpgrade rust-toolset | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade cargo-debuginfoUpgrade clippy-debuginfoUpgrade rust-analyzerUpgrade rust-lldbUpgrade rust-toolsetUpgrade rust-debuginfoUpgrade rustfmt-debuginfoUpgrade rustUpgrade rust-docUpgrade rust-std-static-wasm32-unknown-unknownUpgrade rust-srcUpgrade rust-gdbUpgrade rust-debugsourceUpgrade cargoUpgrade rust-cargo-c-debugsourceUpgrade rustfmtUpgrade rust-analyzer-debuginfoUpgrade rust-toolset-srpm-macrosUpgrade cargo-c-debuginfoUpgrade rust-std-staticUpgrade cargo-cUpgrade rust-debugger-commonUpgrade clippyUpgrade rust-std-static-wasm32-wasip1 | Apr 7, 2026 | Dec 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub