VDB
Sign up
HIGH7.5

GHSA-gwfj-pw2x-h6c2

Out of bounds read in simd-json

Details

The affected version of this crate did not guard against accessing memory beyond the range of its input data. A pointer cast to read the data into a 256-bit register could lead to a segmentation fault when the end plus the 32 bytes (256 bit) read would overlap into the next page during string parsing. This allows an attacker to eventually crash a service. The flaw was corrected by using a padding buffer for the last read from the input. So that we are we never read over the boundary of the input data.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/simd-json
Introduced in: 0.1.13Fixed in: 0.1.15

Upgrade simd-json to 0.1.15 or newer (ecosystem crates.io).

References