Vulnerability Description
An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, violating soundness.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cdr Project | Cdr | < 0.2.4 |
Related Weaknesses (CWE)
References
- https://rustsec.org/advisories/RUSTSEC-2021-0012.htmlExploitVendor Advisory
- https://rustsec.org/advisories/RUSTSEC-2021-0012.htmlExploitVendor Advisory
FAQ
What is CVE-2021-26305?
CVE-2021-26305 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, violat...
How severe is CVE-2021-26305?
CVE-2021-26305 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-26305?
Check the references section above for vendor advisories and patch information. Affected products include: Cdr Project Cdr.