/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-c5wm-8p7g-3g72

Published

Last updated

https://images.chainguard.dev/security/CGA-c5wm-8p7g-3g72
Package

rustup

RepositoryWolfi
Latest Update
Fixed
Fixed Version

1.27.1-r4

Aliases
  • GHSA-q445-7m23-qrmw

Severity

Unknown

Summary

openssl's MemBio::get_buf has undefined behavior with empty buffers

Description

Previously, MemBio::get_buf called slice::from_raw_parts with a null-pointer, which violates the functions invariants, leading to undefined behavior. In debug builds this would produce an assertion failure. This is now fixed.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs