rkyv is vulnerable to NULL Pointer Dereference
68
Medium Risk
Affected versions of this package are vulnerable to a null pointer dereference caused by improper handling of null values returned by the allocator in the SharedPointer::alloc process. An attacker can trigger an out-of-memory condition during shared pointer allocation, leading to dereferencing a null pointer through safe deserialization APIs and resulting in a crash or potentially arbitrary code execution.
You are affected if you are using a version that falls within the vulnerable range.
rkyv is vulnerable to NULL Pointer Dereference in versions 0.0.1 - 0.7.45 and 0.8.0 - 0.8.12.
Upgrade the rkyv library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant