MEDIUM5.1
GHSA-m9m5-cg5h-r582
Improper random number generation in nanorand
Details
In versions of nanorand prior to 0.5.1, RandomGen implementations for standard unsigned integers could fail to properly generate numbers, due to using bit-shifting to truncate a 64-bit number, rather than just an as conversion. This often manifested as RNGs returning nothing but 0, including the cryptographically secure ChaCha random number generator.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/nanorand
Introduced in:
0Fixed in: 0.5.1Upgrade nanorand to 0.5.1 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-35926[ADVISORY]
- https://github.com/Absolucy/nanorand-rs/commit/5ba218ac29df4786b002d7d12b47fa0c04a331f2[WEB]
- https://github.com/Absolucy/nanorand-rs[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2020-0089.html[WEB]
- https://twitter.com/aspenluxxxy/status/1336684692284772352[WEB]