Описание
Use of Uninitialized Resource in ash.
An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv may read from uninitialized memory locations.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-45688
- https://github.com/MaikKlein/ash/issues/354
- https://github.com/ash-rs/ash/issues/354
- https://github.com/ash-rs/ash/pull/470
- https://github.com/ash-rs/ash/commit/2c98b6f384a017de031698bd623551a45f24c8f9
- https://github.com/ash-rs/ash/compare/0.33.0...0.33.1
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/ash/RUSTSEC-2021-0090.md
- https://rustsec.org/advisories/RUSTSEC-2021-0090.html
Пакеты
Наименование
ash
rust
Затронутые версииВерсия исправления
< 0.33.1
0.33.1
Связанные уязвимости
CVSS3: 9.8
nvd
около 4 лет назад
An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv may read from uninitialized memory locations.