VDB
Sign up
—

RUSTSEC-2021-0115

`#[zeroize(drop)]` doesn't implement `Drop` for `enum`s

Details

Affected versions of this crate did not implement `Drop` when `#[zeroize(drop)]` was used on an `enum`.

This can result in memory not being zeroed out after dropping it, which is exactly what is intended when adding this attribute.

The flaw was corrected in version 1.2 and `#[zeroize(drop)]` on `enum`s now properly implements `Drop`.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/zeroize_derive
Introduced in: 0.0.0-0Fixed in: 1.1.1

Upgrade zeroize_derive to 1.1.1 or newer (ecosystem crates.io).

References