chore(deps): update rust crate serde_with to v3.21.0 [security] - #326
chore(deps): update rust crate serde_with to v3.21.0 [security]#326renovate[bot] wants to merge 1 commit into
Conversation
|
|
|
|
👋 This PR targeted
|
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This PR contains the following updates:
3.18.0→3.21.03.12.0→3.21.0serde_with: KeyValueMap serialization panics on empty sequence or map entries
GHSA-7gcf-g7xr-8hxj
More information
Details
Summary
The public
KeyValueMapserializer assumes that each mapped element has at least one field or item to use as the map key, but it subtracts1from the caller-visible length before validating that assumption. An application that serializes attacker-controlled data through#[serde_as(as = "KeyValueMap<_>")]can be crashed by an empty inner sequence or map entry.Details
The affected public surface includes:
#[serde_as(as = "KeyValueMap<_>")]values throughserde_json::to_stringor any other Serde serializer`KeyValueMapconversions for sequence and map-backed entries`The root cause is: The
KeyValueMapserializer preallocatingVec::with_capacity(len - 1)orVec::with_capacity(len.unwrap_or(17) - 1)before checking that the element actually contains the required first key field or item.The vulnerable data/control flow is: attacker-controlled empty entry ->
serde_json::to_string->KeyValueMap<TAs>::serialize_as->SeqAsMapSerializer::{serialize_seq,serialize_map}->Vec::with_capacity(len - 1)orVec::with_capacity(len.unwrap_or(17) - 1)-> panicRelevant source locations:
serde_with/src/key_value_map.rs:590serde_with/src/key_value_map.rs:599serde_with/src/key_value_map.rs:613serde_with/src/key_value_map.rs:632serde_with/src/key_value_map.rs:648PoC
Impact
A local attacker who can trigger serialization of attacker-controlled data through
KeyValueMapcan terminate the process, causing a denial of service.Severity
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
serde_with: KeyValueMap serialization panics on empty sequence or map entries
GHSA-7gcf-g7xr-8hxj
More information
Details
Summary
The public
KeyValueMapserializer assumes that each mapped element has at least one field or item to use as the map key, but it subtracts1from the caller-visible length before validating that assumption. An application that serializes attacker-controlled data through#[serde_as(as = "KeyValueMap<_>")]can be crashed by an empty inner sequence or map entry.Details
The affected public surface includes:
#[serde_as(as = "KeyValueMap<_>")]values throughserde_json::to_stringor any other Serde serializer`KeyValueMapconversions for sequence and map-backed entries`The root cause is: The
KeyValueMapserializer preallocatingVec::with_capacity(len - 1)orVec::with_capacity(len.unwrap_or(17) - 1)before checking that the element actually contains the required first key field or item.The vulnerable data/control flow is: attacker-controlled empty entry ->
serde_json::to_string->KeyValueMap<TAs>::serialize_as->SeqAsMapSerializer::{serialize_seq,serialize_map}->Vec::with_capacity(len - 1)orVec::with_capacity(len.unwrap_or(17) - 1)-> panicRelevant source locations:
serde_with/src/key_value_map.rs:590serde_with/src/key_value_map.rs:599serde_with/src/key_value_map.rs:613serde_with/src/key_value_map.rs:632serde_with/src/key_value_map.rs:648PoC
Impact
A local attacker who can trigger serialization of attacker-controlled data through
KeyValueMapcan terminate the process, causing a denial of service.Severity
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
jonasbb/serde_with (serde_with)
v3.21.0: serde_with v3.21.0Compare Source
Security
GHSA-7gcf-g7xr-8hxj: KeyValueMap serialization panics on empty sequence or map entries
Bad or attacker controlled values could cause a panic while allocating too large values.
Fixed in #966 by setting a maximum allocation size during the creation of collections like
Vecor sets.Thanks to @7thParkk for reporting the issue.
Added
NoneAsZeroadapter that mapsOption<NonZero*>to a plain integer, encodingNoneas0by @SAY-5 (#486)Changed
Fixed
unused_qualificationsand fix the resulting findings by @lms0806 (#962)v3.20.0: serde_with v3.20.0Compare Source
Added
base58encoding, similar to the existingbase64setup by @mitinarseny (#943)Fixed
base64withschemarssupport by @mitinarseny (#9949)v3.19.0: serde_with v3.19.0Compare Source
Added
Add support for
hashbrownv0.17 (#940)This extends the existing support for
hashbrownto the newly released version.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.