-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability manifests in Block::load where buffer length calculation (block_size - constants) could underflow. This is explicitly called out in both the RustSec advisory and GitLab issue #4. The function directly processes compressed data input and performs the unsafe buffer size calculation that leads to out-of-bounds writes. The function signature matches the code location referenced in all vulnerability descriptions and contains the exact vulnerable arithmetic operation described.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| bam | rust | < 0.1.3 | 0.1.3 |
Ongoing coverage of React2Shell