← Back to CVE List

CVE-2020-36317

Published: 2021-04-11T20:15Z
Last Modified: 2024-11-21T05:29Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics. This bug could result in a memory safety violation when other string APIs assume that UTF-8 encoding is used on the same string. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt