Skip to content
GoogleGHSA-3mv5-343c-w2qg

*This advisory is also published as [RUSTSEC-2023-0074]

LowPublished Dec 14, 2023 · updated Dec 18, 2023

*This advisory is also published as [RUSTSEC-2023-0074](https://rustsec.org/advisories/RUSTSEC-2023-0074.html).* The `Ref` methods `into_ref`, `into_mut`, `into_slice`, and `into_slice_mut` are unsound and may allow safe code to exhibit undefined behavior when used with `Ref<B, T>` where `B` is [`cell::Ref`](https://doc.rust-lang.org/core/cell/struct.Ref.html) or [`cell::RefMut`](https://doc.rust-lang.org/core/cell/struct.RefMut.html). Note that these methods remain sound when used with `B` types other than `cell::Ref` or `cell::RefMut`. See https://github.com/google/zerocopy/issues/716 for a more in-depth analysis. The current plan is to yank the affected versions soon. See https://github.com/google/zerocopy/issues/679 for more detail.

GitHub advisory

Affected versions

PackageAffectedFixed in
zerocopy
crates.io
< 0.2.90.2.9
< 0.3.20.3.2
< 0.4.10.4.1
< 0.5.20.5.2
< 0.6.60.6.6
< 0.7.310.7.31
Details and references

More Google advisories

All Google
Advisory
Microsoft VSCode: XSS
HighJan 4, 2024
PostgreSQL: Array Set Element Memory Corruption
HighJan 3, 2024
Kakadu: JPX fragmented list vulnerability
HighDec 15, 2023
Microsoft Edge: Arbitrary Perms
MediumDec 14, 2023
Envoy: ALTS Bug
MediumNov 29, 2023
Oracle VM VirtualBox: Integer Overflow Leading To Out-Of-Bounds Read in virtioNetR3CtrlMac
HighNov 16, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.