GHSA-69fv-gw6g-8ccg

    Dashboard / Vulnerabilities / GHSA-69fv-gw6g-8ccg

    GHSA-69fv-gw6g-8ccg

    Published: 25 Aug 2021Last Modified: 12 Sept 2024

    Summary: Potential memory corruption in arrayfire

    Details: The attribute repr() added to enums to be compatible with C-FFI caused memory corruption on MSVC toolchain. arrayfire crates <= version 3.5.0 do not have this issue when used with Rust versions 1.27 or earlier. The issue only started to appear since Rust version 1.28. The issue seems to be interlinked with which version of Rust is being used. The issue was fixed in crate 3.6.0.

    Affected packages

    Package

    Name: arrayfire

    Purl: pkg:cargo/arrayfire

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.6.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High