{"id":"GHSA-x54v-qxxr-93qc","summary":"Missing release of memory in sized-chunks","details":"Chunk:\n\n* Array size is not checked when constructed with unit() and pair().\n* Array size is not checked when constructed with From\u003cInlineArray\u003cA, T\u003e\u003e.\n* Clone and insert_from are not panic-safe; A panicking iterator causes memory safety issues with them.\n\nInlineArray:\n\n* Generates unaligned references for types with a large alignment requirement.\n","aliases":["CVE-2020-25791","CVE-2020-25792","CVE-2020-25793","CVE-2020-25794","CVE-2020-25795","CVE-2020-25796","GHSA-64gv-qg2v-vxv6","GHSA-9p9m-9xww-qjcx","GHSA-fqpx-cq8x-9wp4","GHSA-mp6f-p9gp-vpj9","GHSA-rfgg-vccr-m46m","RUSTSEC-2020-0041"],"modified":"2023-11-02T05:41:09.900372Z","published":"2021-08-25T20:45:01Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-08-19T21:21:52Z","nvd_published_at":"2020-09-19T21:15:00Z","cwe_ids":["CWE-401"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25795"},{"type":"WEB","url":"https://github.com/bodil/sized-chunks/issues/11"},{"type":"PACKAGE","url":"https://github.com/bodil/sized-chunks"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2020-0041.html"}],"affected":[{"package":{"name":"sized-chunks","ecosystem":"crates.io","purl":"pkg:cargo/sized-chunks"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-x54v-qxxr-93qc/GHSA-x54v-qxxr-93qc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}