HIGH7.5
GHSA-mm4m-qg48-f7wc
Improper Synchronization and Race Condition in vm-memory
Details
rust-vmm vm-memory before 0.1.1 and 0.2.x before 0.2.1 allows attackers to cause a denial of service (loss of IP networking) because read_obj and write_obj do not properly access memory. This affects aarch64 (with musl or glibc) and x86_64 (with musl).
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/vm-memory
Introduced in:
0Fixed in: 0.1.1Upgrade vm-memory to 0.1.1 or newer (ecosystem crates.io).
crates.io/vm-memory
Introduced in:
0.2.0Fixed in: 0.2.1Upgrade vm-memory to 0.2.1 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-13759[ADVISORY]
- https://github.com/rust-vmm/vm-memory/issues/93[WEB]
- https://github.com/rust-vmm/vm-memory[PACKAGE]
- https://github.com/rust-vmm/vm-memory/releases/tag/v0.1.1[WEB]
- https://github.com/rust-vmm/vm-memory/releases/tag/v0.2.1[WEB]
- https://rustsec.org/advisories/RUSTSEC-2020-0157.html[WEB]