VDB
Sign up
MEDIUM

GHSA-jf5h-cf95-w759

Optional `Deserialize` implementations lacking validation

Details

When activating the non-default feature `serialize`, most structs implement `serde::Deserialize` without sufficient validation. This allows breaking invariants in safe code, leading to:

* Undefined behavior in `as_string()` methods (which use `std::str::from_utf8_unchecked()` internally). * Panics due to failed assertions.

See https://github.com/gz/rust-cpuid/issues/43.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/raw-cpuid
Introduced in: 3.1.0Fixed in: 9.1.1

Upgrade raw-cpuid to 9.1.1 or newer (ecosystem crates.io).

References