CVE-2022-36124

HIGH7.5EPSS 3.0%

Apache Avro Rust SDK's Reader could consume memory beyond allowed constraints

發布日:2022/8/9修改日:2026/5/19
也稱為:GHSA-wcm8-86x6-8mv3PYSEC-2022-43180

描述

It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

參考連結(4)