CRITICAL9.8
GHSA-8fgg-5v78-6g76
Deserializing an array can free uninitialized memory in byte_struct
Details
Byte_struct stack and unpack structure as raw bytes with packed or bit field layout. An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a certain deserialization method panics.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/byte_struct
Introduced in:
0Fixed in: 0.6.1Upgrade byte_struct to 0.6.1 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-28033[ADVISORY]
- https://github.com/wwylele/byte-struct-rs/issues/1[WEB]
- https://github.com/wwylele/byte-struct-rs/commit/a535678377de12bc6bc22620c5f59bcc1369f76f[WEB]
- https://github.com/wwylele/byte-struct-rs[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2021-0032.html[WEB]