CVE-2023-28448: Versionize::deserialize implementation for FamStructWrapper<T> is lacking bound checks, potentially leading to out of bounds memory accesses
An issue was discovered in the Versionize::deserialize
implementation provided by the versionize
crate for vmm_sys_util::fam::FamStructWrapper
, which can lead to out of bounds memory accesses.
References
- github.com/advisories/GHSA-8vxc-r5wp-vgvc
- github.com/firecracker-microvm/versionize
- github.com/firecracker-microvm/versionize/commit/a57a051ba006cfa3b41a0532f484df759e008d47
- github.com/firecracker-microvm/versionize/pull/53
- github.com/firecracker-microvm/versionize/releases/tag/v0.1.10
- github.com/firecracker-microvm/versionize/security/advisories/GHSA-8vxc-r5wp-vgvc
- nvd.nist.gov/vuln/detail/CVE-2023-28448
- rustsec.org/advisories/RUSTSEC-2023-0030.html
Detect and mitigate CVE-2023-28448 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →