Lucene search

K
rustsecRustsecRUSTSEC-2022-0068
HistoryNov 30, 2022 - 12:00 p.m.

out-of-bounds read possible when setting list-of-pointers

2022-11-3012:00:00
rustsec.org
11
memory exfiltration
data consumer
c++ cap'n proto

EPSS

0.002

Percentile

51.6%

If a message consumer expects data
of type “list of pointers”,
and if the consumer performs certain specific actions on such data,
then a message producer can cause the consumer to read out-of-bounds memory.
This could trigger a process crash in the consumer,
or in some cases could allow exfiltration of private in-memory data.

The C++ Cap’n Proto library is also affected by this bug.
See the advisory
on the main Cap’n Proto repo for a succinct description of
the exact circumstances in which the problem can arise.