{"id":"GHSA-4fcv-w3qc-ppgg","aliases":["RUSTSEC-2025-0022"],"url":"https://o3.security/vulnerability/GHSA-4fcv-w3qc-ppgg","summary":"rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`","details":"When a `Some(...)` value was passed to the `properties` argument of either of these functions, a use-after-free would result.\n\nIn practice this would nearly always result in OpenSSL treating the properties as an empty string (due to `CString::drop`'s behavior).\n\nThe maintainers thank [quitbug](https://github.com/quitbug/) for reporting this vulnerability to us.","published":"2025-04-04T20:31:08Z","modified":"2026-09-10T03:50:56.938932795Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"openssl","fixedVersion":"0.10.72"}],"fix":{"url":"https://github.com/sfackler/rust-openssl/pull/2390","label":"sfackler/rust-openssl#2390"},"references":[{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/pull/2390"},{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/commit/87085bd67896b7f92e6de35d081f607a334beae4"},{"type":"PACKAGE","url":"https://github.com/sfackler/rust-openssl"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0022.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:56.938932795Z"}}