{"id":"GHSA-cvmj-47v9-35m9","aliases":["RUSTSEC-2021-0154"],"url":"https://o3.security/vulnerability/GHSA-cvmj-47v9-35m9","summary":"FUSE-Rust: Uninitalized memory read and leak caused by fuser crate","details":"During the creation of a new libfuse session with `fuse_session_new`, the operation list was passed as NULL incorrectly. libfuse expects this argument to always point to list of operations. This caused uninitialized memory read and leaks in libfuse.so.","published":"2025-09-15T17:30:21Z","modified":"2025-10-28T06:29:24.209631Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"fuser","fixedVersion":"0.16.0"}],"fix":{"url":"https://github.com/cberner/fuser/pull/390","label":"cberner/fuser#390"},"references":[{"type":"WEB","url":"https://github.com/cberner/fuser/pull/390"},{"type":"PACKAGE","url":"https://github.com/cberner/fuser"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2021-0154.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-28T06:29:24.209631Z"}}