HIGHcrates.io →
rustix's `rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosion
rustix's `rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosion
Affected packages
- rustix
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/bytecodealliance/rustix/security/advisories/GHSA-c827-hfw6-qwvm
- https://nvd.nist.gov/vuln/detail/CVE-2024-43806
- https://github.com/imsnif/bandwhich/issues/284
- https://github.com/imsnif/bandwhich/issues/284#issuecomment-1754321993
- https://github.com/bytecodealliance/rustix/commit/31fd98ca723b93cc6101a3e29843ea5cf094e159
- https://github.com/bytecodealliance/rustix/commit/87481a97f4364d12d5d6f30cdd025a0fc509b8ec
- https://github.com/bytecodealliance/rustix/commit/df3c3a192cf144af0da8a57417fb4addbdc611f6
- https://github.com/bytecodealliance/rustix/commit/eecece4a84fc58eafdc809cc2cedd374dee876a5
- https://discord.com/channels/273534239310479360/1161137828395237556
- https://github.com/bytecodealliance/rustix
Structured record: https://osv.dev/vulnerability/GHSA-c827-hfw6-qwvm
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta