CVE-2020-36323
Summary
| CVE | CVE-2020-36323 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-14 07:15:00 UTC |
| Updated | 2023-11-07 03:22:00 UTC |
| Description | In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borrowed string changes after its length is checked. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| API soundness issue in join() implementation of [Borrow<str>] · Issue #80335 · rust-lang/rust · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 32 Update: rust-1.51.0-3.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Fixes API soundness issue in join() by Qwaz · Pull Request #81728 · rust-lang/rust · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 34 Update: rust-1.51.0-3.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Fixes API soundness issue in join() by Qwaz · Pull Request #81728 · rust-lang/rust · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 33 Update: rust-1.51.0-3.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: rust-1.51.0-3.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Fixes API soundness issue in join() by Qwaz · Pull Request #81728 · rust-lang/rust · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 34 Update: rust-1.51.0-3.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: rust-1.51.0-3.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159344 Oracle Enterprise Linux Security Update for rust-toolset:ol8 (ELSA-2021-3063)
- 239538 Red Hat Update for rust-toolset:rhel8 (RHSA-2021:3063)
- 281294 Fedora Security Update for rust (FEDORA-2021-b1ba54add6)
- 281295 Fedora Security Update for rust (FEDORA-2021-d7f74f0250)
- 281296 Fedora Security Update for rust (FEDORA-2021-d0ba1901ca)
- 353979 Amazon Linux Security Advisory for rust : ALAS2-2022-1816
- 377347 Alibaba Cloud Linux Security Update for rust-toolset:rhel8 (ALINUX3-SA-2021:0061)
- 501921 Alpine Linux Security Update for rust
- 505391 Alpine Linux Security Update for rust
- 900062 CBL-Mariner Linux Security Update for rust 1.47.0
- 902939 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (4081)
- 940361 AlmaLinux Security Update for rust-toolset:rhel8 (ALSA-2021:3063)
- 960098 Rocky Linux Security Update for rust-toolset:rhel8 (RLSA-2021:3063)