VDB
Sign up
—

RUSTSEC-2021-0154

Uninitalized memory read & leak caused by fuser crate

Details

During creation of new libfuse session with `fuse_session_new` operation list was passed as NULL incorrectly. libfuse expects this argument to always point to list of operations. This caused uninitialized memory read and leaks in libfuse.so

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/fuser
Introduced in: 0.0.0-0Fixed in: 0.16.0

Upgrade fuser to 0.16.0 or newer (ecosystem crates.io).

References