GHSA-8vxc-r5wp-vgvc
Versionize::deserialize implementation for FamStructWrapper<T> is lacking bound checks, potentially leading to out of bounds memory accesses
Details
### Impact
An issue was discovered in the `Versionize::deserialize` implementation provided by the `versionize` crate for `vmm_sys_util::fam::FamStructWrapper`, which can lead to out of bounds memory accesses.
### Patches
The impact started with version 0.1.1. The issue was corrected in version 0.1.10 by inserting a check that verifies, for any deserialized header, the lengths of compared flexible arrays are equal and aborting deserialization otherwise.
### Workarounds \-
### References - https://github.com/firecracker-microvm/versionize/pull/53
Are you affected?
Enter the version of the package you're using.
Affected packages
0.1.1Fixed in: 0.1.10Upgrade versionize to 0.1.10 or newer (ecosystem crates.io).
References
- https://github.com/firecracker-microvm/versionize/security/advisories/GHSA-8vxc-r5wp-vgvc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-28448[ADVISORY]
- https://github.com/firecracker-microvm/versionize/pull/53[WEB]
- https://github.com/firecracker-microvm/versionize/commit/a57a051ba006cfa3b41a0532f484df759e008d47[WEB]
- https://github.com/firecracker-microvm/versionize[PACKAGE]
- https://github.com/firecracker-microvm/versionize/releases/tag/v0.1.10[WEB]
- https://rustsec.org/advisories/RUSTSEC-2023-0030.html[WEB]