cbcvebase.
CVE-2020-36323
published 2021-04-14

CVE-2020-36323: In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to…

high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borrowed string changes after its length is checked.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianrustc< rustc 1.53.0+dfsg1-1 (bookworm)rustc 1.53.0+dfsg1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_rust_1.47.0-3_on_cbl_mariner_1.0
rust-langrust< 1.52.01.52.0

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
osv8.2HIGH