Skip to content

RUSTSEC-2025-0022: Use-After-Free in Md::fetch and Cipher::fetch #89

@github-actions

Description

@github-actions
Details
Package openssl
Version 0.10.68
URL rust-openssl/rust-openssl#2390
Patched Versions >=0.10.72
Unaffected Versions <0.10.39
Aliases GHSA-4fcv-w3qc-ppgg

When a Some(...) value was passed to the properties argument of either of these functions, a use-after-free would result.

In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to CString::drop's behavior).

The maintainers thank quitbug for reporting this vulnerability to us.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions