Skip to content

RUSTSEC-2025-0022: Use-After-Free in Md::fetch and Cipher::fetch #5933

@github-actions

Description

@github-actions

Use-After-Free in Md::fetch and Cipher::fetch

Details
Package openssl
Version 0.10.71
URL sfackler/rust-openssl#2390
Date 2025-04-04
Patched versions >=0.10.72
Unaffected versions <0.10.39

When a Some(...) value was passed to the properties argument of either of these functions, a use-after-free would result.

In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to CString::drop's behavior).

The maintainers thank quitbug for reporting this vulnerability to us.

See advisory page for additional details.

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityPull requests that address a security vulnerability

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions