VDB
Sign up
HIGH7.3

GHSA-9frf-r7c7-j2vg

Out of bounds write in stackvector

Details

StackVec::extend used the lower and upper bounds from an Iterator's size_hint to determine how many items to push into the stack based vector. If the size_hint implementation returned a lower bound that was larger than the upper bound, StackVec would write out of bounds and overwrite memory on the stack. As mentioned by the size_hint documentation, size_hint is mainly for optimization and incorrect implementations should not lead to memory safety issues.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/stackvector
Introduced in: 0Fixed in: 1.0.9

Upgrade stackvector to 1.0.9 or newer (ecosystem crates.io).

References