MEDIUM
GHSA-fjx5-qpf4-xjf2
Parsing borsh messages with ZST which are not-copy/clone is unsound
Details
Affected versions of borsh cause undefined behavior when zero-sized-types (ZST) are parsed and the Copy/Clone traits are not implemented/derived. For instance if 1000 instances of a ZST are deserialized, and the ZST is not copy (this can be achieved through a singleton), then accessing/writing to deserialized data will cause a segmentation fault.
There is currently no way for borsh to read data without also providing a Rust type. Therefore, if you are not using ZST for serialization, then you are not affected by this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/borsh
Introduced in:
0Fixed in: 1.0.0-alpha.1Upgrade borsh to 1.0.0-alpha.1 or newer (ecosystem crates.io).