CVE-2020-35861

NameCVE-2020-35861
DescriptionAn issue was discovered in the bumpalo crate before 3.2.1 for Rust. The realloc feature allows the reading of unknown memory. Attackers can potentially read cryptographic keys.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs955151

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rust-bumpalo (PTS)bullseye3.4.0-1fixed
bookworm3.12.0-1fixed
sid, trixie3.16.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rust-bumpalosource(unstable)3.2.1-1955151

Notes

https://rustsec.org/advisories/RUSTSEC-2020-0006.html
https://github.com/fitzgen/bumpalo/issues/69

Search for package or bug name: Reporting problems