Vulnerability DatabaseRUSTSEC-2023-0038

RUSTSEC-2023-0038
Rust vulnerability analysis and mitigation

Overview

RUSTSEC-2023-0038 is a vulnerability in the sequoia-openpgp Rust library that leads to out-of-bounds array access resulting in a panic. The issue was discovered in May 2023 and affects all versions of sequoia-openpgp since its initial 1.0 release until version 1.16.0, which contains the fix. The vulnerability is present in the packet parser component of the library (Sequoia Announce).

Technical details

The vulnerability is caused by a parsing error where attacker-controlled input can trigger the packet parser to access an array using an out-of-range array index. Due to Rust's safety mechanisms, this results in a panic rather than memory corruption. The issue was independently discovered by Paul Schaub (vanitasvitae) and Alexander Kjäll (capitol), and was subsequently patched by Justus Winter (Sequoia Announce).

Impact

The vulnerability has been classified as low severity since it can only be exploited to cause a program crash (denial of service) through a panic. The attacker cannot read from or write to the process's address space, limiting the potential impact to service disruption (Sequoia Announce).

Mitigation and workarounds

The vulnerability has been fixed in sequoia-openpgp version 1.16.0. Additionally, backported fixes are available in version 1.8.1 for Debian Testing and version 1.1.1 for Debian Stable. Users are recommended to upgrade to these patched versions to mitigate the vulnerability (Sequoia Announce).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-2cgv-28vr-rv6jHIGH8.8
  • RustRust
  • libcrux-intrinsics
NoYesDec 04, 2025
GHSA-xrv8-2pf5-f3q7MEDIUM6
  • RustRust
  • nitro-tpm-pcr-compute
NoYesDec 05, 2025
GHSA-mj73-j457-8x9qLOW2.7
  • RustRust
  • maxminddb
NoYesDec 02, 2025
GHSA-pq5v-rwp8-p7gmLOW2.7
  • RustRust
  • rtvm-interpreter
NoNoDec 02, 2025
RUSTSEC-2025-0133N/AN/A
  • RustRust
  • libcrux-intrinsics
NoYesDec 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management