CVE-2018-1000657 describes a buffer overflow vulnerability within the Rust standard library's VecDeque::reserve() function, affecting Rust versions 1.3.0 through 1.21.0. This flaw could lead to arbitrary code execution. With a CVSS score of 7.8 (High), the vulnerability is local, low complexity, and could result in high impact to confidentiality, integrity, and availability. While no public proof-of-concept exploits or active exploitation have been observed, the vulnerability has garnered some community discussion and media coverage, including an article on Hacker News.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.0, < 1.22.0CPE matchmatch criteria | cpe:2.3:a:rust-lang:rust:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.