GHSA-jcr6-4frq-9gjj

    Dashboard / Vulnerabilities / GHSA-jcr6-4frq-9gjj

    GHSA-jcr6-4frq-9gjj

    Published: 11 Sept 2023Last Modified: 10 Sept 2026

    Summary: Users vulnerable to unaligned read of `*const *const c_char` pointer

    Details: Affected versions dereference a potentially unaligned pointer. The pointer is commonly unaligned in practice, resulting in undefined behavior. In some build modes, this is observable as a panic followed by abort. In other build modes the UB may manifest in some other way, including the possibility of working correctly in some architectures. The crate is not currently maintained, so a patched version is not available. ## Recommended alternatives - [`uzers`](https://crates.io/crates/uzers) (an actively maintained fork of the `users` crate) - [`sysinfo`](https://crates.io/crates/sysinfo)

    Affected packages

    Package

    Name: users

    Purl: pkg:cargo/users

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-jcr6-4frq-9gjj | CVE-DB