RUSTSEC-2021-0032
Dashboard / Vulnerabilities / RUSTSEC-2021-0032
RUSTSEC-2021-0032
Summary: Deserializing an array can drop uninitialized memory on panic
Details: The `read_bytes_default_le` function for `[T; n]` arrays, used to deserialize arrays of `T` from bytes created a `[T; n]` array with `std::mem::uninitialized` and then called `T`'s deserialization method. If `T`'s deserialization method panicked, the uninitialized memory could drop invalid objects. This flaw was corrected in `a535678` by removing the unsafe block and using a `.map` function to deserialize each element of the array instead.
References: https://crates.io/crates/byte_struct, https://rustsec.org/advisories/RUSTSEC-2021-0032.html, https://github.com/wwylele/byte-struct-rs/issues/1
Affected packages
Package
Name: byte_struct
Purl: pkg:cargo/byte_struct
Affected ranges
Type: SEMVER
Events:
