UBUNTU-CVE-2025-55159

Source
https://ubuntu.com/security/CVE-2025-55159
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-55159.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-55159
Upstream
Published
2025-08-11T23:15:00Z
Modified
2025-08-14T04:58:01Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the getdisjointmut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing access to uninitialized memory. This could lead to undefined behavior or potential crashes. This has been fixed in slab 0.4.11. A workaround for this issue involves to avoid using getdisjointmut with indices that might be beyond the slab's actual length.

References

Affected packages

Ubuntu:Pro:20.04:LTS / rust-slab

Package

Name
rust-slab
Purl
pkg:deb/ubuntu/rust-slab@0.4.1-1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.4.1-1

Ubuntu:22.04:LTS / rust-slab

Package

Name
rust-slab
Purl
pkg:deb/ubuntu/rust-slab@0.4.4-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.4.1-1
0.4.4-1

Ubuntu:24.04:LTS / rust-slab

Package

Name
rust-slab
Purl
pkg:deb/ubuntu/rust-slab@0.4.9-1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.4.4-1
0.4.9-1

Ubuntu:25.04 / rust-slab

Package

Name
rust-slab
Purl
pkg:deb/ubuntu/rust-slab@0.4.9-1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.4.9-1