QID 353978

Date Published: 2022-07-18

QID 353978: Amazon Linux Security Advisory for rust : ALAS2-2022-1817

A race condition flaw was found in rust's std::fs::remove_dir_all function.
Rust applications that use this function may be vulnerable to a race condition where an unprivileged attacker can trick the application into deleting files and directories, causing an impact on system data integrity.
If the application is privileged, an attacker can possibly delete files they would not usually have access to. (
( CVE-2022-21658)



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.3 severity.
  • CVSS V2 rated as Medium - 3.3 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2-2022-1817 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 353978

    Software Advisories
    Advisory ID Software Component Link
    ALAS2-2022-1817 Amazon Linux 2 URL Logo alas.aws.amazon.com/AL2/ALAS-2022-1817.html