PT-2026-71091 · Rustfs · Rustfs
CVE-2026-73288
·
Published
2026-08-12
·
Updated
2026-08-12
CVSS v4.0
6.1
Medium
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustFS versions prior to 1.0.0-rc.1
Description
Object Lock enforcement in the
crates/ecstore/src/bucket/object lock/objectlock sys.rs file incorrectly handles certain error conditions. Specifically, the functions check object lock for deletion(), delete prefix(), and lifecycle and scanner sweeps treat ConfigNotFound, unreadable .metadata.bin data, or unparseable metadata as if no lock configuration exists. This allows objects under COMPLIANCE retention—a strict Write Once Read Many (WORM) state that prevents deletion—to be deleted or expired.Recommendations
Update to version 1.0.0-rc.1.
Exploit
Fix
Protection Mechanism Failure
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rustfs