GHSA-3qx8-rv27-j6gp
Undefined behaviour in `kvm_ioctls::ioctls::vm::VmFd::create_device`
Details
An issue was identified in the `VmFd::create_device function`, leading to undefined behavior and miscompilations on rustc 1.82.0 and newer due to the function's violation of Rust's pointer safety rules.
The function downcasted a mutable reference to its `struct kvm_create_device` argument to an immutable pointer, and then proceeded to pass this pointer to a mutating system call. Rustc 1.82.0 and newer elides subsequent reads of this structure's fields, meaning code will not see the value written by the kernel into the `fd` member. Instead, the code will observe the value that this field was initialized to prior to calling `VmFd::create_device` (usually, 0).
The issue started in kvm-ioctls 0.1.0 and was fixed in 0.19.1 by correctly using a mutable pointer.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.19.1Upgrade kvm-ioctls to 0.19.1 or newer (ecosystem crates.io).