CVE-2020-35920: Medium severity socket2 vulnerability

Published Dec 31, 2020
·
Updated

An issue was discovered in the socket2 crate before 0.3.16 for Rust. It has false expectations about the std::net::SocketAddr memory representation.

Other sources

The socket2 crate has assumed std::net::SocketAddrV4 and std::net::SocketAddrV6 have the same memory layout as the system C representation sockaddr. It has simply casted the pointers to convert the socket addresses to the system representation. The standard library does not say anything about the memory layout, and this will cause invalid memory access if the standard library changes the implementation. No warnings or errors will be emitted once the change happens.

GitHub

Affected Software

3 affected componentsFixes available
rust/net2<0.2.36
0.2.36
rust/socket2<0.3.16
0.3.16
rust-lang Socket2 Rust<0.3.16

Event History

Dec 31, 2020
CVE Published
via MITRE·08:17 AM
Data Sourced
via MITRE·08:17 AM
Description
Aug 25, 2021
Advisory Published
via GitHub·08:50 PM

Frequently Asked Questions

1

What is CVE-2020-35920?

CVE-2020-35920 is an issue discovered in the socket2 crate before 0.3.16 for Rust.

2

What is the impact of CVE-2020-35920?

CVE-2020-35920 could lead to unexpected behavior and potential security vulnerabilities in applications using the affected socket2 crate.

3

How can I mitigate the vulnerability in CVE-2020-35920?

To mitigate the vulnerability in CVE-2020-35920, update your Rust projects to use version 0.3.16 or later of the socket2 crate.

4

Where can I find more information about CVE-2020-35920?

You can find more information about CVE-2020-35920 in the advisory at https://rustsec.org/advisories/RUSTSEC-2020-0079.html.

5

What is the severity rating of CVE-2020-35920?

CVE-2020-35920 has a severity rating of medium, with a CVSS score of 5.5.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203