rust-zserio
Activity
- Latest release
- 4mo ago
- Total releases
- 18
- Cadence
- ~13 days
- Last 12 months
- 2
Details
- License
- BSD-3-Clause
- First release
- Sep 11, 2023
| Version | Released | |
|---|---|---|
0.5.4
unknown
|
0.5.4
unknown
Dependencies (1)
|
|
0.5.3
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.5.3
unknown
Dependencies (1)
|
|
0.5.2
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.5.2
unknown
Dependencies (1)
|
|
0.5.1
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.5.1
unknown
Dependencies (1)
|
|
0.5.0
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (1)
|
|
0.4.0
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.4.0
unknown
Dependencies (1)
|
|
0.3.2
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.3.2
unknown
Dependencies (1)
|
|
0.3.1
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.3.1
unknown
Dependencies (1)
|
|
0.2.0
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.2.0
unknown
Dependencies (20)
+ 12 more |
|
0.1.0
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (19)
+ 11 more |
|
0.0.8
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.0.8
unknown
Dependencies (17)
+ 9 more |
|
0.0.7
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.0.7
unknown
Dependencies (17)
+ 9 more |
|
0.0.6
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.0.6
unknown
Dependencies (17)
+ 9 more |
|
0.0.5
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.0.5
unknown
Dependencies (16)
+ 8 more |
|
0.0.4
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.0.4
unknown
Dependencies (16)
+ 8 more |
|
0.0.3
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.0.3
unknown
Dependencies (14)
+ 6 more |
|
0.0.2
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.0.2
unknown
Dependencies (14)
+ 6 more |
|
0.0.1
unknown
1 CVE
GHSA-fpf5-4jw8-67x8
May 07, 2026
rust-zserio has Unbounded Memory Allocation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactWhen deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. PatchesPlease cherry-pick 57f5fb. Workarounds
Fixed in
0.5.4
References Updated May 07, 2026 · Source: OSV.dev |
0.0.1
unknown
Dependencies (14)
+ 6 more |