VDB
Sign up
HIGH7.5

GHSA-xr7r-88qv-q7hm

Out of bounds write in serde_cbor

Details

Affected versions of this crate did not properly check if semantic tags were nested excessively during deserialization. This allows an attacker to craft small (< 1 kB) CBOR documents that cause a stack overflow. The flaw was corrected by limiting the allowed number of nested tags.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/serde_cbor
Introduced in: 0Fixed in: 0.10.2

Upgrade serde_cbor to 0.10.2 or newer (ecosystem crates.io).

References