VDB
Sign up
MEDIUM5.5

GHSA-qxjq-v4wf-ppvh

Out of bounds read in dync

Details

VecCopy::data is created as a Vec of u8 but can be used to store and retrieve elements of different types leading to misaligned access.

The issue was resolved in v0.5.0 by replacing data being stored by Vec<u8> with a custom managed pointer. Elements are now stored and retrieved using types with proper alignment corresponding to original types.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/dync
Introduced in: 0Fixed in: 0.5.0

Upgrade dync to 0.5.0 or newer (ecosystem crates.io).

References