CVE-2020-11105
NixOS vulnerability analysis and mitigation

Overview

An issue was discovered in USC iLab cereal through version 1.3.0, identified as CVE-2020-11105. The vulnerability relates to the caching mechanism of std::shared_ptr values, where the raw pointer address is used as a unique identifier. This vulnerability has been confirmed to affect multiple versions of Aurora MySQL, including versions 3.07.0, 3.06.0, 3.05.2, 3.04.2, 2.12.1, and 2.11.5 (Aurora MySQL).

Technical details

The vulnerability stems from the software's implementation of caching std::shared_ptr values using the raw pointer as a unique identifier. The issue becomes problematic when a std::shared_ptr variable goes out of scope and is freed, and a new std::shared_ptr is allocated at the same memory address. This creates a situation where serialization fidelity becomes dependent upon memory layout, potentially leading to incorrect data serialization (GitHub Issue).

Impact

The vulnerability can result in incorrect data serialization where the deserialized output does not match the original input. For example, when serializing a sequence of true and false values using shared pointers, the deserialized output might incorrectly return all true values due to the memory address reuse issue (GitHub Issue).

Mitigation and workarounds

The vulnerability has been addressed in various Aurora MySQL versions. Users are recommended to upgrade to patched versions including 3.07.0, 3.06.0, 3.05.2, 3.04.2, 2.12.1, or 2.11.5 which contain the fix for CVE-2020-11105 (Aurora MySQL).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management