HIGH7.5
GHSA-w5cr-frph-hw7f
Use of uninitialized buffer in rkyv
Details
An issue was discovered in the rkyv crate before 0.6.0 for Rust. When an archive is created via serialization, the archive content may contain uninitialized values of certain parts of a struct.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-31919[ADVISORY]
- https://github.com/djkoloski/rkyv/issues/113[WEB]
- https://github.com/djkoloski/rkyv/commit/9c65ae9c2c67dd949b5c3aba9b8eba6da802ab7e[WEB]
- https://github.com/djkoloski/rkyv/commit/f141b560523a20557db6540576d153010bd18712[WEB]
- https://rustsec.org/advisories/RUSTSEC-2021-0054.html[WEB]