VDB
Sign up
MEDIUM

GHSA-fjx5-qpf4-xjf2

Parsing borsh messages with ZST which are not-copy/clone is unsound

Details

Affected versions of borsh cause undefined behavior when zero-sized-types (ZST) are parsed and the Copy/Clone traits are not implemented/derived. For instance if 1000 instances of a ZST are deserialized, and the ZST is not copy (this can be achieved through a singleton), then accessing/writing to deserialized data will cause a segmentation fault.

There is currently no way for borsh to read data without also providing a Rust type. Therefore, if you are not using ZST for serialization, then you are not affected by this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/borsh
Introduced in: 0Fixed in: 1.0.0-alpha.1

Upgrade borsh to 1.0.0-alpha.1 or newer (ecosystem crates.io).

References