vulnerability

Oracle Linux: CVE-2021-29922: ELSA-2021-4270: rust-toolset:ol8 security, bug fix, and enhancement update (MODERATE)

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
Published
Mar 29, 2021
Added
Nov 17, 2021
Modified
Dec 3, 2025

Description

library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.
A flaw was found in rust. Extraneous zero characters at the beginning of an IP address string are not properly considered which can allow an attacker to bypass IP-based access controls. The highest threat from this vulnerability is to data confidentiality and integrity.

Solutions

oracle-linux-upgrade-cargooracle-linux-upgrade-cargo-docoracle-linux-upgrade-clippyoracle-linux-upgrade-rlsoracle-linux-upgrade-rustoracle-linux-upgrade-rust-analysisoracle-linux-upgrade-rust-debugger-commonoracle-linux-upgrade-rust-docoracle-linux-upgrade-rustfmtoracle-linux-upgrade-rust-gdboracle-linux-upgrade-rust-lldboracle-linux-upgrade-rust-srcoracle-linux-upgrade-rust-std-staticoracle-linux-upgrade-rust-std-static-wasm32-unknown-unknownoracle-linux-upgrade-rust-toolset
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.