CVE-2021-45707
Summary
| CVE | CVE-2021-45707 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-27 00:15:00 UTC |
| Updated | 2022-10-28 17:48:00 UTC |
| Description | An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Nix Project |
Nix |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| RUSTSEC-2021-0119: nix: Out-of-bounds write in nix::unistd::getgrouplist › RustSec Advisory Database |
MISC |
rustsec.org |
|
| raw.githubusercontent.com/rustsec/advisory-db/main/crates/nix/RUSTSEC-2021-0119.md |
MISC |
raw.githubusercontent.com |
|
| Out-of-bounds write in nix::unistd::getgrouplist · GHSA-wgrg-5h56-jg27 · GitHub Advisory Database · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184800 Debian Security Update for rust-nix (CVE-2021-45707)
- 904934 Common Base Linux Mariner (CBL-Mariner) Security Update for rpm-ostree (12418)
- 905139 Common Base Linux Mariner (CBL-Mariner) Security Update for rpm-ostree (12627)