GHSA-9hfg-pxr6-q4vp
Dashboard / Vulnerabilities / GHSA-9hfg-pxr6-q4vp
GHSA-9hfg-pxr6-q4vp
Summary: Use of a Broken or Risky Cryptographic Algorithm in crypto2
Details: The implementation does not enforce alignment requirements on input slices while incorrectly assuming 4-byte alignment through an unsafe call to std::slice::from_raw_parts_mut, which breaks the contract and introduces undefined behavior. This affects Chacha20 encryption and decryption in crypto2.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-45709, https://github.com/shadowsocks/crypto2/issues/27, https://github.com/shadowsocks/crypto2, https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/crypto2/RUSTSEC-2021-0121.md, https://rustsec.org/advisories/RUSTSEC-2021-0121.html
Affected packages
Package
Name: crypto2
Purl: pkg:cargo/crypto2
Affected ranges
Type: SEMVER
Events:
