Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3933-wvjf-pcvc

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Out of bounds access in lucet-runtime-internals

An embedding using affected versions of lucet-runtime configured to use non-default Wasm globals sizes of more than 4KiB, or compiled in debug mode without optimizations, could leak data from the signal handler stack to guest programs. This can potentially cause data from the embedding host to leak to guest programs or cause corruption of guest program memory. This flaw was resolved by correcting the sigstack allocation logic.

Пакеты

Наименование

lucet-runtime-internals

rust
Затронутые версииВерсия исправления

< 0.4.3

0.4.3

Наименование

lucet-runtime-internals

rust
Затронутые версииВерсия исправления

>= 0.5.0, < 0.5.1

0.5.1

EPSS

Процентиль: 62%
0.00433
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-125
CWE-787

Связанные уязвимости

CVSS3: 9.1
nvd
около 5 лет назад

An issue was discovered in the lucet-runtime-internals crate before 0.5.1 for Rust. It mishandles sigstack allocation. Guest programs may be able to obtain sensitive information, or guest programs can experience memory corruption.

EPSS

Процентиль: 62%
0.00433
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-125
CWE-787