Use After Free Affecting actix-codec package, versions <0.3.0-beta.1


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
1.22% (86th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Use After Free vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-RUST-ACTIXCODEC-1013438
  • published28 Sept 2020
  • disclosed30 Jan 2020
  • creditUnknown

Introduced: 30 Jan 2020

CVE-2020-35902  (opens in a new tab)
CWE-416  (opens in a new tab)

How to fix?

Upgrade actix-codec to version 0.3.0-beta.1 or higher.

Overview

actix-codec is an Utilities for encoding and decoding frames.

Affected versions of this package are vulnerable to Use After Free. Affected versions of this crate did not require the buffer wrapped in Framed to be pinned, but treated it as if it had a fixed location in memory. This may result in a use-after-free. The flaw was corrected by making the affected functions accept Pin<&mut Self> instead of &mut self.

CVSS Scores

version 3.1