CVE-2026-40034

EUVD-2026-31831
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 27.7%
Debian logo
Debian Releases
Debian Product
Codename
rust-gix-submodule
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rust-gix
jammy
dne
noble
dne
questing
ignored
resolute
needs-triage
rust-gix-submodule
jammy
dne
noble
dne
questing
ignored
resolute
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
cargo
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
cargo-c
Amazon Linux 2023
0:0.10.19-1.amzn2023.0.4
fixed
cargo-c-debuginfo
Amazon Linux 2023
0:0.10.19-1.amzn2023.0.4
fixed
cargo-debuginfo
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
clippy
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
clippy-debuginfo
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-analyzer
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-analyzer-debuginfo
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-cargo-c-debugsource
Amazon Linux 2023
0:0.10.19-1.amzn2023.0.4
fixed
rust-debugger-common
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-debuginfo
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-debugsource
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-doc
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-gdb
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-lldb
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-src
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-std-static
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-std-static-wasm32-unknown-unknown
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-std-static-wasm32-wasip1
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-toolset
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rust-toolset-srpm-macros
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rustfmt
Amazon Linux 2
0:1.97.0-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
rustfmt-debuginfo
Amazon Linux 2023
0:1.97.0-1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
rust
Azure Linux 3.0
0:1.75.0-30.azl3
fixed