GHSA-9pwq-gcrx-wghh: Infoleak
A soundness bug in buffa's OwnedView<V> allowed safe Rust code to trigger a use-after-free. The OwnedView::decode constructor transmuted a borrowed slice to &'static [u8], and the Deref implementation exposed the promoted 'static lifetime on borrowed view fields (such as &'static str and &'static [u8]) to callers. Because these references appeared to be 'static, the borrow checker permitted them to outlive the OwnedView; once the OwnedView was dropped and its backing buffer freed, those references became dangling, enabling memory corruption, information disclosure of freed heap contents, and cross-thread misuse — all without any unsafe code in the calling application. Users are advised to update to the latest patched version of buffa.
Thank you to hackerone.com/suul for reporting this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rust/buffato a version that resolves this vulnerability.Fixed in 0.7.0
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications using buffa's OwnedView::decode are exposed if they retain borrowed view fields such as &str or &[u8] beyond the lifetime of the OwnedView that backs them. The issue can be triggered from safe Rust code in the calling application.
What can result from successful exploitation?
Dangling references can be used after the OwnedView is dropped and its backing buffer is freed. The reported impacts include memory corruption, disclosure of freed heap contents, and cross-thread misuse.
What should teams do to remediate the issue?
Update buffa to the latest patched version. The provided information does not identify an alternative mitigation for deployments that cannot update immediately.