
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-26951 is a critical vulnerability discovered in the calamine crate versions before 0.17.0 for Rust, reported on January 6, 2021, and issued on January 30, 2021. The vulnerability affects the memory handling functionality in the Sectors::get component, allowing attackers to potentially overwrite heap-memory locations (RustSec Advisory).
The vulnerability stems from improper memory management where Vec::set_len is called to increase the length of a vector without properly claiming additional memory. The critical issue occurs when the crate performs Read operations on uninitialized memory that was extended using Vec::set_len. This behavior is classified as undefined behavior (UB) in Rust. The vulnerability has received a CVSS v3.1 score of 9.8 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network accessibility with no required privileges or user interaction (RustSec Advisory, NVD).
The vulnerability can lead to overwriting of active entities in adjacent heap memory, potentially causing severe security implications. The high CVSS score indicates critical impacts on confidentiality, integrity, and availability of affected systems (RustSec Advisory).
The vulnerability is remotely exploitable with low attack complexity, requiring no privileges or user interaction. The network attack vector makes it particularly dangerous as it can be exploited from remote locations (RustSec Advisory).
The vulnerability has been patched in calamine version 0.17.0 and later. Users are strongly advised to upgrade to version 0.17.0 or newer to mitigate this security risk (RustSec Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."