High severityNVD Advisory· Published Aug 9, 2022· Updated Aug 3, 2024
Memory overconsumption in Avro Rust SDK
CVE-2022-36124
Description
It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-avrocrates.io | < 0.14.0 | 0.14.0 |
Affected products
2- Range: <0.14.0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-wcm8-86x6-8mv3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-36124ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/avro/PYSEC-2022-43180.yamlghsaWEB
- lists.apache.org/thread/kj429rzo1xxjgz058qqqg0y7c0p512zoghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.