CRITICAL9.8
GHSA-37jj-wp7g-7wj4
Read of uninitialized memory in cdr
Details
An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, violating soundness.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-26305[ADVISORY]
- https://github.com/hrektts/cdr-rs/issues/10[WEB]
- https://github.com/hrektts/cdr-rs/pull/11[WEB]
- https://github.com/hrektts/cdr-rs/commit/0e6006de464caa331643f86cd2d9ba3b32b09833[WEB]
- https://github.com/hrektts/cdr-rs[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2021-0012.html[WEB]