diff --git a/advisories/github-reviewed/2024/12/GHSA-3qx8-rv27-j6gp/GHSA-3qx8-rv27-j6gp.json b/advisories/github-reviewed/2024/12/GHSA-3qx8-rv27-j6gp/GHSA-3qx8-rv27-j6gp.json new file mode 100644 index 00000000000..997b26bf4c1 --- /dev/null +++ b/advisories/github-reviewed/2024/12/GHSA-3qx8-rv27-j6gp/GHSA-3qx8-rv27-j6gp.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qx8-rv27-j6gp", + "modified": "2024-12-23T19:26:37Z", + "published": "2024-12-23T19:26:37Z", + "aliases": [], + "summary": "Undefined behaviour in `kvm_ioctls::ioctls::vm::VmFd::create_device`", + "details": "An issue was identified in the `VmFd::create_device function`, leading to undefined behavior and miscompilations on rustc 1.82.0 and newer due to the function's violation of Rust's pointer safety rules.\n\nThe function downcasted a mutable reference to its `struct kvm_create_device` argument to an immutable pointer, and then proceeded to pass this pointer to a mutating system call. Rustc 1.82.0 and newer elides subsequent reads of this structure's fields, meaning code will not see the value written by the kernel into the `fd` member. Instead, the code will observe the value that this field was initialized to prior to calling `VmFd::create_device` (usually, 0).\n\nThe issue started in kvm-ioctls 0.1.0 and was fixed in 0.19.1 by correctly using\na mutable pointer.\n", + "severity": [], + "affected": [ + { + "package": { + "ecosystem": "crates.io", + "name": "kvm-ioctls" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.19.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/rust-vmm/kvm/pull/298" + }, + { + "type": "PACKAGE", + "url": "https://github.com/rust-vmm/kvm-ioctls" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2024-0428.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-12-23T19:26:37Z", + "nvd_published_at": null + } +} \ No newline at end of file