VDB
Sign up
HIGH7.5

GHSA-fpf5-4jw8-67x8

rust-zserio has Unbounded Memory Allocation

Details

### Impact

When deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory.

### Patches

Please cherry-pick [57f5fb](https://github.com/Danaozhong/rust-zserio/commit/57f5fb4a2a8611d58dbcc1a9221349206dd99c3c).

### Workarounds

- Do not accept `zserio`-encoded messages from non-trusted sources. - Allocate a maximum heap amount to `rust-zerio` to avoid impacting other applications.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rust-zserio
Introduced in: 0Fixed in: 0.5.4

Upgrade rust-zserio to 0.5.4 or newer (ecosystem crates.io).

References