CVE-2020-35907: Null Pointer Dereference
Published Dec 31, 2020
·Updated
An issue was discovered in the futures-task crate before 0.3.5 for Rust. futurestask::noopwakerref allows a NULL pointer dereference.
Affected Software
1 affected component
rust-lang Futures-task<0.3.5
Event History
Dec 31, 2020
CVE Published
via MITRE·08:20 AM
Data Sourced
via MITRE·08:20 AM
Description
Frequently Asked Questions
1
What is CVE-2020-35907?
CVE-2020-35907 is an issue discovered in the futures-task crate before version 0.3.5 for Rust.
2
How severe is CVE-2020-35907?
CVE-2020-35907 has a severity rating of 5.5 (medium).
3
What is the affected software?
The affected software is the futures-task crate for Rust with versions up to 0.3.5.
4
What is the vulnerability type of CVE-2020-35907?
CVE-2020-35907 is classified as CWE-476, which is a NULL pointer dereference vulnerability.
5
Is there a fix for CVE-2020-35907?
Yes, the fix for CVE-2020-35907 is to update the futures-task crate to version 0.3.5 or newer.