Vulnerability Details CVE-2020-35859
An issue was discovered in the lucet-runtime-internals crate before 0.5.1 for Rust. It mishandles sigstack allocation. Guest programs may be able to obtain sensitive information, or guest programs can experience memory corruption.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.7%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2020-35859
-
cpe:2.3:a:lucet-runtime-internals_project:lucet-runtime-internals:0.1.1
-
cpe:2.3:a:lucet-runtime-internals_project:lucet-runtime-internals:0.2.0
-
cpe:2.3:a:lucet-runtime-internals_project:lucet-runtime-internals:0.2.1
-
cpe:2.3:a:lucet-runtime-internals_project:lucet-runtime-internals:0.3.0
-
cpe:2.3:a:lucet-runtime-internals_project:lucet-runtime-internals:0.3.1
-
cpe:2.3:a:lucet-runtime-internals_project:lucet-runtime-internals:0.4.1
-
cpe:2.3:a:lucet-runtime-internals_project:lucet-runtime-internals:0.4.3
-
cpe:2.3:a:lucet-runtime-internals_project:lucet-runtime-internals:0.5.0