Skip to content

RUSTSEC-2020-0049: Use-after-free in Framed due to lack of pinning #1

@github-actions

Description

@github-actions

Use-after-free in Framed due to lack of pinning

Details
Package actix-codec
Version 0.4.0-beta.1
URL actix/actix-net#91
Date 2020-01-30
Patched versions >=0.3.0-beta.1

Affected versions of this crate did not require the buffer wrapped in Framed to be pinned,
but treated it as if it had a fixed location in memory. This may result in a use-after-free.

The flaw was corrected by making the affected functions accept Pin<&mut Self> instead of &mut self.

See advisory page for additional details.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions