{"id":"GHSA-qm2p-4w45-v2vr","aliases":["RUSTSEC-2025-0005"],"url":"https://o3.security/vulnerability/GHSA-qm2p-4w45-v2vr","summary":"grcov has an out of bounds write triggered by crafted coverage data","details":"Function `grcov::covdir::get_coverage` uses the `unsafe` function `get_unchecked_mut` without validating that the index is in bounds.\n\nThis results in memory corruption, and could potentially allow arbitrary code execution provided that an attacker can feed the tool crafted coverage data.","published":"2025-02-10T18:07:30Z","modified":"2025-10-28T06:29:25.945179Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"grcov","fixedVersion":"0.8.20"}],"fix":{"url":"https://github.com/mozilla/grcov/commit/c8219563bc91615dd4a27884a5c63f09db8d03bb","label":"mozilla/grcov@c821956"},"references":[{"type":"WEB","url":"https://github.com/mozilla/grcov/commit/c8219563bc91615dd4a27884a5c63f09db8d03bb"},{"type":"WEB","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1917475"},{"type":"PACKAGE","url":"https://github.com/mozilla/grcov"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0005.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-28T06:29:25.945179Z"}}