MEDIUM
GHSA-jf5h-cf95-w759
Optional `Deserialize` implementations lacking validation
Details
When activating the non-default feature `serialize`, most structs implement `serde::Deserialize` without sufficient validation. This allows breaking invariants in safe code, leading to:
* Undefined behavior in `as_string()` methods (which use `std::str::from_utf8_unchecked()` internally). * Panics due to failed assertions.
See https://github.com/gz/rust-cpuid/issues/43.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/raw-cpuid
Introduced in:
3.1.0Fixed in: 9.1.1Upgrade raw-cpuid to 9.1.1 or newer (ecosystem crates.io).