{"id":"GHSA-x3f4-45xf-rjm7","aliases":["RUSTSEC-2024-0400"],"url":"https://o3.security/vulnerability/GHSA-x3f4-45xf-rjm7","summary":"`ruzstd` uninit and out-of-bounds memory reads","details":"Affected versions of `ruzstd` miscalculate the length of the allocated and init section of its internal `RingBuffer`, leading to uninitialized or out-of-bounds reads in `copy_bytes_overshooting` of up to 15 bytes.\n\nThis may result in up to 15 bytes of memory contents being written into the decoded data when decompressing a crafted archive. This may occur multiple times per archive.\n","published":"2024-12-02T21:34:27Z","modified":"2026-09-10T03:50:21.770869461Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"ruzstd","fixedVersion":"0.7.3"}],"fix":{"url":"https://github.com/KillingSpark/zstd-rs/pull/76","label":"KillingSpark/zstd-rs#76"},"references":[{"type":"WEB","url":"https://github.com/KillingSpark/zstd-rs/issues/75"},{"type":"WEB","url":"https://github.com/KillingSpark/zstd-rs/pull/76"},{"type":"PACKAGE","url":"https://github.com/KillingSpark/zstd-rs"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2024-0400.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:21.770869461Z"}}