VDB
Sign up
CRITICAL9.8

GHSA-mmc9-pwm7-qj5w

Unaligned memory access in rand_core

Details

### Impact Affected versions of this crate violated alignment when casting byte slices to integer slices, resulting in undefined behavior. `rand_core::BlockRng::next_u64` and `rand_core::BlockRng::fill_bytes` are affected.

### Patches The flaw was corrected by Ralf Jung and Diggory Hardy for `rand_core >= 0.4.2`.

### Workarounds None.

### References See [Rand's changelog](https://github.com/rust-random/rand/blob/master/rand_core/CHANGELOG.md#050---2019-06-06).

### For more information If you have any questions or comments about this advisory, [open an issue in the Rand repository](https://github.com/rust-random/rand/issues/new/choose).

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rand_core
Introduced in: 0.4.0Fixed in: 0.4.2

Upgrade rand_core to 0.4.2 or newer (ecosystem crates.io).

crates.io/rand_core
Introduced in: 0Fixed in: 0.3.1

Upgrade rand_core to 0.3.1 or newer (ecosystem crates.io).

References