Critical severity9.1NVD Advisory· Published Aug 7, 2021· Updated Jun 17, 2026
CVE-2021-29922
CVE-2021-29922
Description
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Rust/Rustdescription
Patches
Vulnerability mechanics
References
6- github.com/rust-lang/rust/pull/83652nvdPatchThird Party Advisory
- github.com/rust-lang/rust/issues/83648nvdExploitIssue TrackingPatchThird Party Advisory
- github.com/sickcodes/security/blob/master/advisories/SICK-2021-015.mdnvdExploitThird Party Advisory
- defcon.org/html/defcon-29/dc-29-speakers.htmlnvdThird Party Advisory
- doc.rust-lang.org/beta/std/net/struct.Ipv4Addr.htmlnvdVendor Advisory
- security.gentoo.org/glsa/202210-09nvdThird Party Advisory
News mentions
0No linked articles in our index yet.