—
RUSTSEC-2026-0233
Crafted archives can cause a use-after-free during deserialization
상세
Insufficient archive range validation could allow a crafted archive to reach `ArchivedString::deserialize` with an invalid pointer. A reported reproducer used `rkyv::from_bytes` to deserialize a struct containing strings, a vector, a box, and an optional hash map. AddressSanitizer detected a heap use-after-free during string deserialization.
The flaw could be triggered through the safe checked deserialization API when processing malicious archive bytes. Version 0.8.17 rejects the malformed archive during validation. Users who process untrusted archives should upgrade to 0.8.17 or later.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
crates.io / rkyv
최초 영향 버전:
0.8.0-rc.1 수정 버전: 0.8.17 Upgrade rkyv to 0.8.17 or newer (ecosystem crates.io).
참고
- https://crates.io/crates/rkyv [PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2026-0233.html [ADVISORY]
- https://github.com/rkyv/rkyv/issues/666 [REPORT]
- https://github.com/rkyv/rkyv/commit/3c9d07fbff5949261bef38d00ab160b129bd9d3a [WEB]
- https://github.com/rkyv/rkyv/commit/107772907c4e839fa67900385f0d4814e7d15e42 [WEB]