CVE-2021-29939

NameCVE-2021-29939
DescriptionAn issue was discovered in the stackvector crate through 2021-02-19 for Rust. There is an out-of-bounds write in StackVec::extend if size_hint provides certain anomalous data.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs986808

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rust-stackvector (PTS)bullseye1.0.6-3fixed
sid, trixie, bookworm1.1.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rust-stackvectorsource(unstable)1.0.6-3986808

Notes

https://rustsec.org/advisories/RUSTSEC-2021-0048.html

Search for package or bug name: Reporting problems