VDB
Sign up
—

RUSTSEC-2025-0126

Heap-buffer-overflow in nftnl::Batch::with_page_size (nftnl-rs)

Details

A heap-buffer-overflow vulnerability exists in the Rust wrapper for libnftnl, triggered via the nftnl::Batch::with_page_size constructor. When a small or malformed page size is provided, the underlying C code allocates an insufficient buffer, leading to out-of-bounds writes during batch initialization.

The flaw was fixed in commit 94a286f by adding an overflow check: ```Rust batch_page_size .checked_add(crate::nft_nlmsg_maxsize()) .expect("batch_page_size is too large and would overflow"); ```

## Mitigation

Upgrade to version `0.9.0` or later, which aborts instead.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/nftnl
Introduced in: 0.0.0-0Fixed in: 0.9.0

Upgrade nftnl to 0.9.0 or newer (ecosystem crates.io).

References