{"id":"GHSA-3qx8-rv27-j6gp","aliases":["RUSTSEC-2024-0428"],"url":"https://o3.security/vulnerability/GHSA-3qx8-rv27-j6gp","summary":"Undefined behaviour in `kvm_ioctls::ioctls::vm::VmFd::create_device`","details":"An issue was identified in the `VmFd::create_device function`, leading to undefined behavior and miscompilations on rustc 1.82.0 and newer due to the function's violation of Rust's pointer safety rules.\n\nThe function downcasted a mutable reference to its `struct kvm_create_device` argument to an immutable pointer, and then proceeded to pass this pointer to a mutating system call. Rustc 1.82.0 and newer elides subsequent reads of this structure's fields, meaning code will not see the value written by the kernel into the `fd` member. Instead, the code will observe the value that this field was initialized to prior to calling `VmFd::create_device` (usually, 0).\n\nThe issue started in kvm-ioctls 0.1.0 and was fixed in 0.19.1 by correctly using\na mutable pointer.\n","published":"2024-12-23T19:26:37Z","modified":"2025-10-28T06:29:22.787282Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"kvm-ioctls","fixedVersion":"0.19.1"}],"fix":{"url":"https://github.com/rust-vmm/kvm/pull/298","label":"rust-vmm/kvm#298"},"references":[{"type":"WEB","url":"https://github.com/rust-vmm/kvm/pull/298"},{"type":"PACKAGE","url":"https://github.com/rust-vmm/kvm-ioctls"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2024-0428.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-28T06:29:22.787282Z"}}