CVE-2020-25792 describes an array bounds error in the sized-chunks Rust crate (through version 0.6.2), specifically within the Chunk implementation's pair() function where array sizes are not properly validated. This vulnerability carries a CVSS v3.1 score of 7.5 (HIGH), indicating a network-exploitable flaw with low attack complexity that can lead to high availability impact. Despite its severity, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.6.2CPE matchmatch criteria | cpe:2.3:a:sized-chunks_project:sized-chunks:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
sized-chunks vulnerabilities
Mar 23, 2026Array size is not checked in sized-chunks
Aug 25, 2021An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with pair().
Sep 8, 2020