RUSTSEC-2023-0074

    Dashboard / Vulnerabilities / RUSTSEC-2023-0074

    RUSTSEC-2023-0074

    Published: 14 Dec 2023Last Modified: 10 Feb 2024

    Summary: Some Ref methods are unsound with some type parameters

    Details: The `Ref` methods `into_ref`, `into_mut`, `into_slice`, and `into_slice_mut` are unsound and may allow safe code to exhibit undefined behavior when used with `Ref<B, T>` where `B` is [`cell::Ref`](https://doc.rust-lang.org/core/cell/struct.Ref.html) or [`cell::RefMut`](https://doc.rust-lang.org/core/cell/struct.RefMut.html). Note that these methods remain sound when used with `B` types other than `cell::Ref` or `cell::RefMut`. See https://github.com/google/zerocopy/issues/716 for a more in-depth analysis. The current plan is to yank the affected versions soon. See https://github.com/google/zerocopy/issues/679 for more detail.

    Affected packages

    Package

    Name: zerocopy

    Purl: pkg:cargo/zerocopy

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.2.2
    Fixed -0.2.9

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2023-0074 | CVE-DB