CVE-2021-45688: Critical severity ash-aio project ash-aio vulnerability
Published Dec 26, 2021
·Updated
An issue was discovered in the ash crate before 0.33.1 for Rust. util::readspv may read from uninitialized memory locations.
Affected Software
2 affected components
Ash Project Ash Rust<0.33.1
Ash-rs Ash Rust<0.33.1
Event History
Dec 26, 2021
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
Description
Dec 27, 2021
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45688?
CVE-2021-45688 is classified as a medium severity vulnerability due to the potential for reading uninitialized memory.
2
How do I fix CVE-2021-45688?
To fix CVE-2021-45688, upgrade the ash crate to version 0.33.1 or later.
3
What specific issues does CVE-2021-45688 address?
CVE-2021-45688 addresses the issue of uninitialized memory being accessed by the util::read_spv function in the ash crate.
4
What versions of the ash crate are affected by CVE-2021-45688?
CVE-2021-45688 affects all versions of the ash crate prior to 0.33.1.
5
What programming language is impacted by CVE-2021-45688?
CVE-2021-45688 impacts Rust programming language projects that utilize the ash crate.