A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could potentially result in application instability or other unforeseen consequences.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade rustUpgrade rust-toolset-srpm-macrosUpgrade rust-debugger-commonUpgrade rust-std-staticUpgrade rust-srcUpgrade cargoUpgrade rust-docUpgrade clippyUpgrade rustfmtUpgrade rust-toolsetUpgrade rust-gdbUpgrade rust-analyzer | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade cargoUpgrade rust-toolset-srpm-macrosUpgrade rust-analyzer-debuginfoUpgrade rust-cargo-c-debugsourceUpgrade rust-std-static-wasm32-wasip1Upgrade rust-debugger-commonUpgrade rust-std-staticUpgrade rustfmtUpgrade cargo-c-debuginfoUpgrade clippyUpgrade cargo-cUpgrade clippy-debuginfoUpgrade cargo-debuginfoUpgrade rust-std-static-wasm32-unknown-unknownUpgrade rust-srcUpgrade rust-docUpgrade rustfmt-debuginfoUpgrade rust-lldbUpgrade rustUpgrade rust-analyzerUpgrade rust-debuginfoUpgrade rust-debugsourceUpgrade rust-gdbUpgrade rust-toolset | Apr 7, 2026 | Dec 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub