An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because xcb::xproto::GetAtomNameReply::name() calls std::str::fromutf8unchecked() on unvalidated bytes from an X server.
{
"binaries": [
{
"binary_version": "0.9.0-2",
"binary_name": "librust-xcb+debug-all-dev"
},
{
"binary_version": "0.9.0-2",
"binary_name": "librust-xcb+present-dev"
},
{
"binary_version": "0.9.0-2",
"binary_name": "librust-xcb+x11-dev"
},
{
"binary_version": "0.9.0-2",
"binary_name": "librust-xcb+xfixes-dev"
},
{
"binary_version": "0.9.0-2",
"binary_name": "librust-xcb+xlib-xcb-dev"
},
{
"binary_version": "0.9.0-2",
"binary_name": "librust-xcb-dev"
}
]
}