GHSA-8fgg-5v78-6g76
Dashboard / Vulnerabilities / GHSA-8fgg-5v78-6g76
GHSA-8fgg-5v78-6g76
Published: 25 Aug 2021Last Modified: 8 Nov 2023
Aliases:
Summary: Deserializing an array can free uninitialized memory in byte_struct
Details: Byte_struct stack and unpack structure as raw bytes with packed or bit field layout. An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a certain deserialization method panics.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-28033, https://github.com/wwylele/byte-struct-rs/issues/1, https://github.com/wwylele/byte-struct-rs/commit/a535678377de12bc6bc22620c5f59bcc1369f76f, https://github.com/wwylele/byte-struct-rs, https://rustsec.org/advisories/RUSTSEC-2021-0032.html
Affected packages
Package
Name: byte_struct
Purl: pkg:cargo/byte_struct
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.6.1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
