CyberzSOC

Applicability
← Back to CVE-2024-24576

CVE-2024-24576

rust-lang

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

Red Hat CSAF/VEX
precedence 100 · revised 2025-11-21
34 not affected
OSV.dev (incl. GHSA)
precedence 80 · revised 2026-08-12
1 affected 1 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2025-11-04
1 affected
CVE List v5 (ADP/Vulnrichment)
precedence 55 · revised 2025-11-04
1 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (38)

Product Status Versions Remediation Source
red_hat_enterprise_linux_8:cargo::rust-toolset:rhel8 cargo (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present cargo::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:cargo cargo as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: cargo not applicable csaf_redhat
red_hat_enterprise_linux_8:cargo-doc::rust-toolset:rhel8 cargo-doc (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present cargo-doc::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_8:clippy::rust-toolset:rhel8 clippy (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present clippy::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:clippy clippy as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: clippy not applicable csaf_redhat
red_hat_enterprise_linux_8:rls::rust-toolset:rhel8 rls (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rls::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_8:rust::rust-toolset:rhel8 rust (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust rust as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-analysis::rust-toolset:rhel8 rust-analysis (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-analysis::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-analysis rust-analysis as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-analysis not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-analyzer::rust-toolset:rhel8 rust-analyzer (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-analyzer::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-analyzer rust-analyzer as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-analyzer not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-debugger-common::rust-toolset:rhel8 rust-debugger-common (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-debugger-common::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-debugger-common rust-debugger-common as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-debugger-common not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-doc::rust-toolset:rhel8 rust-doc (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-doc::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-doc rust-doc as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-doc not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-gdb::rust-toolset:rhel8 rust-gdb (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-gdb::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-gdb rust-gdb as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-gdb not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-lldb::rust-toolset:rhel8 rust-lldb (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-lldb::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-lldb rust-lldb as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-lldb not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-src::rust-toolset:rhel8 rust-src (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-src::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-src rust-src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-src not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-std-static::rust-toolset:rhel8 rust-std-static (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-std-static::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-std-static rust-std-static as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-std-static not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-std-static-wasm32-unknown-unknown::rust-toolset:rhel8 rust-std-static-wasm32-unknown-unknown (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-std-static-wasm32-unknown-unknown::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-std-static-wasm32-unknown-unknown rust-std-static-wasm32-unknown-unknown as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-std-static-wasm32-unknown-unknown not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-std-static-wasm32-wasi::rust-toolset:rhel8 rust-std-static-wasm32-wasi (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-std-static-wasm32-wasi::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-std-static-wasm32-wasi rust-std-static-wasm32-wasi as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-std-static-wasm32-wasi not applicable csaf_redhat
red_hat_enterprise_linux_8:rust-toolset::rust-toolset:rhel8 rust-toolset (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust-toolset::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust-toolset rust-toolset as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust-toolset not applicable csaf_redhat
red_hat_enterprise_linux_8:rust.src::rust-toolset:rhel8 rust.src (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rust.src::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rust.src rust.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rust.src not applicable csaf_redhat
red_hat_enterprise_linux_8:rustfmt::rust-toolset:rhel8 rustfmt (rust-toolset:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present rustfmt::rust-toolset:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:rustfmt rustfmt as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: rustfmt not applicable csaf_redhat
https://github.com/rust-lang/rust affected < 25ef9e3d85d934b27d9dada2f9dd52b1dc63bb04 vendor fix → 25ef9e3d85d934b27d9dada2f9dd52b1dc63bb04 osv
https://github.com/rust-lang/rust fixed 25ef9e3d85d934b27d9dada2f9dd52b1dc63bb04 vendor fix → 25ef9e3d85d934b27d9dada2f9dd52b1dc63bb04 osv
rust-lang/rust rust-lang · rust affected < 1.77.2 none available cve_cna
rust-lang/rust rust-lang · rust affected < 1.77.2 none available cve_adp

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.