VDB
Sign up
MEDIUM5.1

GHSA-m9m5-cg5h-r582

Improper random number generation in nanorand

Details

In versions of nanorand prior to 0.5.1, RandomGen implementations for standard unsigned integers could fail to properly generate numbers, due to using bit-shifting to truncate a 64-bit number, rather than just an as conversion. This often manifested as RNGs returning nothing but 0, including the cryptographically secure ChaCha random number generator.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/nanorand
Introduced in: 0Fixed in: 0.5.1

Upgrade nanorand to 0.5.1 or newer (ecosystem crates.io).

References