Vulnerability DatabaseRUSTSEC-2021-0064

RUSTSEC-2021-0064
Rust vulnerability analysis and mitigation

Overview

The RUSTSEC-2021-0064 advisory pertains to the cpuid-bool crate, which was marked as unmaintained on May 6, 2021. The crate has been renamed to cpufeatures as part of a broader initiative to support additional CPU architectures beyond x86, particularly ARM platforms (RustCrypto Utils).

Technical details

The change involved renaming the cpuid-bool crate to cpufeatures to accommodate a more general approach to CPU feature detection, particularly for supporting ARM architectures alongside existing x86 support. This was implemented through a pull request that reorganized the codebase to better handle multi-architecture support (RustCrypto Utils).

Impact

The impact was primarily on dependency management for projects using the cpuid-bool crate. As the original crate was marked as unmaintained, projects needed to update their dependencies to use the new cpufeatures crate to continue receiving updates and support (RustCrypto Utils).

Mitigation and workarounds

Users are advised to migrate from the cpuid-bool crate to the new cpufeatures crate. The cpufeatures crate is the direct replacement and continues to be maintained with expanded functionality. No further releases will be made to the original cpuid-bool crate (RustCrypto Utils).

Community reactions

The change was well-received by the community, with multiple projects updating their dependencies to accommodate the new crate name. Various projects including Wasmtime, Tari, and others have addressed this advisory in their codebases by either updating their dependencies or acknowledging the need to transition (RustCrypto Utils).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66627HIGH8.4
  • RustRust
  • wasmi
NoYesDec 09, 2025
GHSA-xrv8-2pf5-f3q7MEDIUM6
  • RustRust
  • nitro-tpm-pcr-compute
NoYesDec 05, 2025
CVE-2025-67487MEDIUM5.5
  • RustRust
  • static-web-server
NoYesDec 09, 2025
CVE-2025-66622LOW1.3
  • RustRust
  • matrix-sdk-base
NoYesDec 09, 2025
RUSTSEC-2025-0135N/AN/A
  • RustRust
  • matrix-sdk-base
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management