Critical severity9.1NVD Advisory· Published Dec 31, 2020· Updated Jun 17, 2026
CVE-2020-35859
CVE-2020-35859
Description
An issue was discovered in the lucet-runtime-internals crate before 0.5.1 for Rust. It mishandles sigstack allocation. Guest programs may be able to obtain sensitive information, or guest programs can experience memory corruption.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lucet-runtime-internalscrates.io | < 0.4.3 | 0.4.3 |
lucet-runtime-internalscrates.io | >= 0.5.0, < 0.5.1 | 0.5.1 |
Affected products
3- Rust/lucet-runtime-internalsdescription
- cpe:2.3:a:lucet-runtime-internals_project:lucet-runtime-internals:*:*:*:*:*:rust:*:*Range: <0.5.1
Patches
Vulnerability mechanics
References
4- rustsec.org/advisories/RUSTSEC-2020-0004.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-3933-wvjf-pcvcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-35859ghsaADVISORY
- github.com/bytecodealliance/lucet/pull/401ghsaWEB
News mentions
0No linked articles in our index yet.