VDB
Sign up
—

RUSTSEC-2025-0142

Segmentation fault and invalid memory read in `mnl::cb_run`

Details

The function `mnl::cb_run` is marked as safe but exhibits unsound behavior when processing malformed Netlink message buffers.

Passing a crafted byte slice to `mnl::cb_run` can trigger memory violations. The function does not sufficiently validate the input buffer structure before processing, leading to out-of-bounds reads.

This vulnerability allows an attacker to cause a Denial of Service (segmentation fault) or potentially read unmapped memory by providing a malformed Netlink message.

The underlying issue is a bug in `libmnl` where during validation `nlh->nlmsg_len` is cast to an `int` and becomes negative if `nlmsg_len` is greater than `INT_MAX`. This causes the validation to succeed even if the buffer is too small for the message. This has been fixed in `libmnl` but still affects version 1.0.5.

The issue in `mnl` was fixed in commit `cd51bdc` by checking the validity of netlink messages passed to `mnl::cb_run`.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/mnl
Introduced in: 0.0.0-0Fixed in: 0.3.1

Upgrade mnl to 0.3.1 or newer (ecosystem crates.io).

References