VDB
Sign up
HIGH7.5

GHSA-mh6h-f25p-98f8

Uncontrolled memory consumption in protobuf

Details

Affected versions of this crate called Vec::reserve() on user-supplied input. This allows an attacker to cause an Out of Memory condition while calling the vulnerable method on untrusted data.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/protobuf
Introduced in: 0Fixed in: 2.6.0

Upgrade protobuf to 2.6.0 or newer (ecosystem crates.io).

References