Skip to content

Conversation

@alexanderkjall
Copy link
Contributor

Information taken from: GHSA-423w-p2w9-r7vq

Note that this have a slightly different version range than the github advisory, and marks version 0.10.0 as vulnerable also.

Based on running the PoC against 0.10.0 and also reading the code here:

https://docs.rs/aes-gcm/0.10.0/src/aes_gcm/lib.rs.html#247
https://docs.rs/aes-gcm/0.10.2/src/aes_gcm/lib.rs.html#287-311
https://docs.rs/aes-gcm/0.10.3/src/aes_gcm/lib.rs.html#287-311

I think that 0.10.0 is also vulnerable.

@tarcieri is it ok if this gets published in rustsec?

@tarcieri
Copy link
Member

Yes that's fine. I'm a little surprised one for this didn't actually get filed already.

@djc djc merged commit 0c07b5e into rustsec:main Dec 29, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants