Vulnerability DatabaseGHSA-wwxp-hxh6-8gf8

GHSA-wwxp-hxh6-8gf8
Rust vulnerability analysis and mitigation

Overview

The binaryvecio crate contains memory safety violations in its binaryreadtoref and binarywritefromref functions (GHSA-wwxp-hxh6-8gf8). The vulnerability was discovered and disclosed in October 2025, affecting all versions up to 0.1.12. The issue exists in the Rust package binaryvecio, which is now archived and unmaintained (GitHub Advisory, RustSec Advisory).

Technical details

The vulnerability stems from unsafe implementations in two functions that accept a single reference (&T or &mut T) but allow multiplication by n to create slices, potentially causing stack buffer overflow when n > 1. The functions use fromrawparts to create slices larger than the underlying allocation, which violates Rust's memory safety guarantees. The vulnerability has been assigned a CVSS score of 7.3 (High severity) and is categorized under CWE-120 (Buffer Copy without Checking Size of Input) (GitHub Advisory).

Impact

When exploited, this vulnerability can lead to stack-based buffer overflow, potentially causing memory corruption and undefined behavior. The impact metrics indicate high severity for confidentiality, integrity, and availability of the vulnerable system (GitHub Advisory).

Mitigation and workarounds

There are no patched versions available as the repository is archived and unmaintained. Users are advised to discontinue use of this crate and seek alternative solutions (RustSec Advisory).

Community reactions

The maintainer of the original codebase has confirmed that the repository is thoroughly deprecated and stated that no code from that repository should be in use (GitHub PR).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-wwxp-hxh6-8gf8HIGH7.3
  • RustRust
  • binary_vec_io
NoNoOct 22, 2025
GHSA-x77x-7mmh-cxv3MEDIUM5.5
  • RustRust
  • ncurses
NoNoOct 22, 2025
CVE-2025-62711LOW2.1
  • RustRust
  • wasmtime
NoYesOct 24, 2025
GHSA-xcpm-76hf-c9ccLOW2
  • RustRust
  • borrowck_sacrifices
NoYesOct 22, 2025
GHSA-fp5x-7m4q-449fLOW2
  • RustRust
  • direct_ring_buffer
NoYesOct 21, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management