vulnerability
FreeBSD: VID-ee26f513-826e-11ec-8be6-d4c9ef517024 (CVE-2022-21658): Rust -- Race condition enabling symlink following
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 3 | (AV:L/AC:M/Au:N/C:N/I:P/A:P) | Jan 31, 2022 | Nov 4, 2022 | Mar 25, 2026 |
Severity
3
CVSS
(AV:L/AC:M/Au:N/C:N/I:P/A:P)
Published
Jan 31, 2022
Added
Nov 4, 2022
Modified
Mar 25, 2026
Description
The Rust Security Response WG was notified that the std::fs::remove_dir_all standard library function is vulnerable to a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn't otherwise access or delete.
Solutions
freebsd-upgrade-package-rustfreebsd-upgrade-package-rust-nightly
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.