RUSTSEC-2022-0052
Dashboard / Vulnerabilities / RUSTSEC-2022-0052
Summary: `os_socketaddr` invalidly assumes the memory layout of std::net::SocketAddr
Details: The [`os_socketaddr`](https://crates.io/crates/os_socketaddr) crate has assumed `std::net::SocketAddrV4` and `std::net::SocketAddrV6` have the same memory layout as the system C representation `sockaddr`. It has simply casted the pointers to convert the socket addresses to the system representation. These layout were [changed into idiomatic rust types](https://github.com/rust-lang/rust/pull/78802) in nightly `std`. Starting from rustc 1.64 the affected versions of this crate will have undefined behaviour.
References: https://crates.io/crates/os_socketaddr, https://rustsec.org/advisories/RUSTSEC-2022-0052.html, https://github.com/a-ba/os_socketaddr/issues/3
Affected packages
Package
Name: os_socketaddr
Purl: pkg:cargo/os_socketaddr
Affected ranges
Type: SEMVER
Events:
