VDB
Sign up
MEDIUM

GHSA-x3f4-45xf-rjm7

`ruzstd` uninit and out-of-bounds memory reads

Details

Affected versions of `ruzstd` miscalculate the length of the allocated and init section of its internal `RingBuffer`, leading to uninitialized or out-of-bounds reads in `copy_bytes_overshooting` of up to 15 bytes.

This may result in up to 15 bytes of memory contents being written into the decoded data when decompressing a crafted archive. This may occur multiple times per archive.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/ruzstd
Introduced in: 0.7.0Fixed in: 0.7.3

Upgrade ruzstd to 0.7.3 or newer (ecosystem crates.io).

References