{"id":"GHSA-x3f4-45xf-rjm7","summary":"`ruzstd` uninit and out-of-bounds memory reads","details":"Affected versions of `ruzstd` miscalculate the length of the allocated and init section of its internal `RingBuffer`, leading to uninitialized or out-of-bounds reads in `copy_bytes_overshooting` of up to 15 bytes.\n\nThis may result in up to 15 bytes of memory contents being written into the decoded data when decompressing a crafted archive. This may occur multiple times per archive.\n","aliases":["RUSTSEC-2024-0400"],"modified":"2026-09-10T03:50:21.770869461Z","published":"2024-12-02T21:34:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-12-02T21:34:27Z","nvd_published_at":null,"cwe_ids":["CWE-125"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/KillingSpark/zstd-rs/issues/75"},{"type":"WEB","url":"https://github.com/KillingSpark/zstd-rs/pull/76"},{"type":"PACKAGE","url":"https://github.com/KillingSpark/zstd-rs"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2024-0400.html"}],"affected":[{"package":{"name":"ruzstd","ecosystem":"crates.io","purl":"pkg:cargo/ruzstd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.7.0"},{"fixed":"0.7.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-x3f4-45xf-rjm7/GHSA-x3f4-45xf-rjm7.json"}}],"schema_version":"1.9.0"}