
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in the socket2 crate before version 0.3.16 for Rust. The vulnerability stems from false expectations about the std::net::SocketAddr memory representation, where the crate incorrectly assumed that std::net::SocketAddrV4 and std::net::SocketAddrV6 have the same memory layout as the system C representation sockaddr (RustSec Advisory).
The vulnerability arises from the socket2 crate's assumption about memory layouts, where it directly casts pointers to convert socket addresses to system representation. The standard library makes no guarantees about memory layout, which could lead to invalid memory access if the standard library implementation changes. This issue has been assigned a CVSS Score of 5.5 (MEDIUM) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (RustSec Advisory).
The vulnerability could result in invalid memory access if the standard library changes its implementation. No warnings or errors would be emitted when such changes occur, potentially leading to high availability impact while confidentiality and integrity remain unaffected (RustSec Advisory).
The vulnerability requires local access with low attack complexity and low privileges. No user interaction is needed to exploit this vulnerability (RustSec Advisory).
The issue has been patched in socket2 version 0.3.16 and later. Users should upgrade to this version or newer to address the vulnerability (RustSec Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."