rustsec / rustsec/advisory-db

Add multiple security advisories for various crates

Open
#2,839 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
1.2k
Forks
544
Avg merge
1d 10h
Merged PRs (30d)
45

Description

Hi RustSec team,

I have identified several security vulnerabilities in the following Rust crates. These issues have already been reported to their respective maintainers via GitHub Issues.

Could you please review and consider adding them to the Advisory Database?

List of Vulnerabilities:
Crate Name Issue Link Bug Type Status
emap https://github.com/yegor256/emap/issues/168 double-free Reported
Caja https://github.com/EmanuelGCC/Caja/issues/1 Potential Out-of-bounds Reported
metacall https://github.com/metacall/core/issues/618 double‑free Reported
binpack-rust https://github.com/Disservin/binpack-rust/issues/17 out-of-bound Reported
AutoVec https://github.com/lluvz/AutoVec/issues/1 out-of-bound Reported
trk-io https://github.com/imeka/trk-io/issues/24 out-of-bound Reported
rustdx https://github.com/zjp-CN/rustdx/issues/38 out-of-bound Reported
fuzzyhash-rs https://github.com/rustysec/fuzzyhash-rs/issues/14 out-of-bound Reported
bitchomp https://github.com/KingPEPSALT/bitchomp/issues/5 double free Reported
fourq_rust https://github.com/982945902/fourq_rust/issues/1 UB Reported
rust-dahl-salso https://github.com/dbdahl/rust-dahl-salso/issues/1 OOB Reported
accessor https://github.com/toku-sa-n/accessor/issues/49 OOB Reported
aeron-rs https://github.com/UnitedTraders/aeron-rs/issues/31 OOB Reported
potato https://github.com/fawdlstty/potato/issues/1 UB Reported

These issues were found during my research into Rust ecosystem security (using static analysis). Please let me know if you need more detailed descriptions or PoCs for any of these to generate the TOML files.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked maintainer issues for each listed crate and the repository's existing advisory TOML files. Done means the reported vulnerabilities have been assessed and the applicable advisories are represented in TOML, with any missing descriptions or PoCs supplied.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.