GHSA-ghc8-5cgm-5rpf

    Dashboard / Vulnerabilities / GHSA-ghc8-5cgm-5rpf

    GHSA-ghc8-5cgm-5rpf

    Published: 11 Sept 2023Last Modified: 10 Feb 2024

    Summary: Inventory fails to prohibit standard library access prior to initialization of Rust standard library runtime

    Details: Affected versions allow arbitrary caller-provided code to execute before the lifetime of `main`. If the caller-provided code accesses particular pieces of the standard library that require an initialized Rust runtime, such as `std::io` or `std::thread`, these may not behave as documented. Panics are likely; UB is possible. The flaw was corrected by enforcing that only code written within the `inventory` crate, which is guaranteed not to access runtime-dependent parts of the standard library, runs before `main`. Caller-provided code is restricted to running at compile time.

    Affected packages

    Package

    Name: inventory

    Purl: pkg:cargo/inventory

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.2.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-ghc8-5cgm-5rpf | CVE-DB