GHSA-mmc9-pwm7-qj5w
Unaligned memory access in rand_core
Details
### Impact Affected versions of this crate violated alignment when casting byte slices to integer slices, resulting in undefined behavior. `rand_core::BlockRng::next_u64` and `rand_core::BlockRng::fill_bytes` are affected.
### Patches The flaw was corrected by Ralf Jung and Diggory Hardy for `rand_core >= 0.4.2`.
### Workarounds None.
### References See [Rand's changelog](https://github.com/rust-random/rand/blob/master/rand_core/CHANGELOG.md#050---2019-06-06).
### For more information If you have any questions or comments about this advisory, [open an issue in the Rand repository](https://github.com/rust-random/rand/issues/new/choose).
Are you affected?
Enter the version of the package you're using.
Affected packages
0.4.0Fixed in: 0.4.2Upgrade rand_core to 0.4.2 or newer (ecosystem crates.io).
0Fixed in: 0.3.1Upgrade rand_core to 0.3.1 or newer (ecosystem crates.io).