RUSTSEC-2020-0004

    Dashboard / Vulnerabilities / RUSTSEC-2020-0004

    RUSTSEC-2020-0004

    Published: 24 Jan 2020Last Modified: 8 Nov 2023

    Summary: sigstack allocation bug can cause memory corruption or leak

    Details: An embedding using affected versions of lucet-runtime configured to use non-default Wasm globals sizes of more than 4KiB, or compiled in debug mode without optimizations, could leak data from the signal handler stack to guest programs. This can potentially cause data from the embedding host to leak to guest programs or cause corruption of guest program memory. This flaw was resolved by correcting the sigstack allocation logic.

    Affected packages

    Package

    Name: lucet-runtime-internals

    Purl: pkg:cargo/lucet-runtime-internals

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -0.4.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2020-0004 | CVE-DB