GHSA-g753-ghr7-q33w: cyfs-base vulnerable to misaligned pointer dereference in `ChunkId::new`
N/A
CVSS Score
Basic Information
CVE ID
-
GHSA ID
EPSS Score
-
CWE
-
Published
6/22/2023
Updated
6/22/2023
KEV Status
No
Technology
Rust
Technical Details
CVSS Vector
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| cyfs-base | rust | <= 0.6.12 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability is clearly located in ChunkId::new as shown in multiple sources:
- The advisory specifically names this function
- The GitHub issue #275 shows the vulnerable code pattern
- The unsafe pointer cast and dereference operation matches the described UB
- The file path matches the commit diff showing the test case addition
- The operation violates Rust's safety requirements by performing unaligned accesses in safe code