Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f7qj-v3vp-4856

Опубликовано: 23 дек. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

libafl has unsound usages of core::slice::from_raw_parts_mut

The library breaks the safety assumptions when using unsafe API slice::from_raw_parts_mut. The pointer passed to from_raw_parts_mut is misaligned by casting u8 to u16 raw pointer directly, which is unsound. The bug is patched by using align_offset, which could make sure the memory address is aligned to 2 bytes for u16.

This was patched in 0.11.2 in the commit.

Пакеты

Наименование

libafl

rust
Затронутые версииВерсия исправления

< 0.11.2

0.11.2

6.9 Medium

CVSS4

6.9 Medium

CVSS4