VDB
Sign up
—

RUSTSEC-2024-0357

`MemBio::get_buf` has undefined behavior with empty buffers

Details

Previously, `MemBio::get_buf` called `slice::from_raw_parts` with a null-pointer, which violates the functions invariants, leading to undefined behavior. In debug builds this would produce an assertion failure. This is now fixed.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/openssl
Introduced in: 0.0.0-0Fixed in: 0.10.66

Upgrade openssl to 0.10.66 or newer (ecosystem crates.io).

References