
Cloud Vulnerability DB
A community-led vulnerabilities database
The raw-cpuid crate before version 9.0.0 for Rust contained multiple soundness issues. The vulnerability was identified with RUSTSEC-2021-0013 and CVE-2021-26306/CVE-2021-26307, discovered and disclosed in January 2021. The affected component is the raw-cpuid crate, which is used for CPU identification in Rust applications (NVD CVE-2021-26306, NVD CVE-2021-26307).
The vulnerability encompasses two main technical issues: First, there are unsound transmute calls within as_string() methods. Second, the crate allows __cpuid_count() calls even when the processor doesn't support the CPUID instruction, leading to deterministic crashes. The CVSS v3.1 base score for these issues ranges from 5.5 to 7.5, indicating medium to high severity (NVD CVE-2021-26306, NVD CVE-2021-26307).
The vulnerability can lead to program crashes and potential memory safety violations. The unsound transmute calls could result in undefined behavior, while the improper CPUID instruction handling causes deterministic crashes on unsupported processors (NVD CVE-2021-26306).
The vulnerability can be triggered through normal usage of the affected methods in the raw-cpuid crate. The issues are particularly concerning as they can cause deterministic crashes and undefined behavior without requiring special privileges or complex exploitation techniques (NVD CVE-2021-26307).
The issues have been fixed in raw-cpuid version 9.0.0. Users are advised to upgrade to this version or later to resolve the vulnerabilities (GitHub PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."