rkyv is vulnerable to NULL Pointer Dereference
68
Medium Risk
Affected versions of this package are vulnerable to a null pointer dereference caused by improper handling of null values returned by the allocator in the SharedPointer::alloc process. An attacker can trigger an out-of-memory condition during shared pointer allocation, leading to dereferencing a null pointer through safe deserialization APIs and resulting in a crash or potentially arbitrary code execution.
You are affected if you are using a version that falls within the vulnerable range.
rkyv is vulnerable to NULL Pointer Dereference in versions 0.0.1 - 0.7.45 and 0.8.0 - 0.8.12.
Upgrade the rkyv library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant