Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS14dzVqLWd2MmctbWptMs4AAxo-
Miscompilation in cortex-m-rt 0.7.1 and 0.7.2
Version 0.7.1 of the cortex-m-rt
crate introduced a regression causing the stack to NOT be eight-byte aligned prior to calling main
(or any other specified entrypoint), violating the stack ABI of AAPCS32, the default ABI used by all Cortex-M targets. This regression is also present in version 0.7.2 of the cortex-m-rt
crate.
This regression can cause certain compiler optimizations (which assume the eight-byte alignment) to produce incorrect behavior at runtime. This incorrect behavior has been observed in real-world applications.
It is advised that ALL users of v0.7.1
and v0.7.2
of the cortex-m-rt
crate update to the latest version (v0.7.3
), AS SOON AS POSSIBLE. Users of v0.7.0
and prior versions of cortex-m-rt
are not affected by this regression.
It will be necessary to rebuild all affected firmware binaries, and flash or deploy the new firmware binaries to affected devices.
Permalink: https://github.com/advisories/GHSA-xw5j-gv2g-mjm2JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14dzVqLWd2MmctbWptMs4AAxo-
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: almost 2 years ago
Identifiers: GHSA-xw5j-gv2g-mjm2
References:
- https://github.com/rust-embedded/cortex-m/discussions/469
- https://rustsec.org/advisories/RUSTSEC-2023-0014.html
- https://github.com/advisories/GHSA-xw5j-gv2g-mjm2
Blast Radius: 0.0
Affected Packages
cargo:cortex-m-rt
Dependent packages: 996Dependent repositories: 1,432
Downloads: 2,804,052 total
Affected Version Ranges: >= 0.7.0, < 0.7.3
Fixed in: 0.7.3
All affected versions: 0.7.0, 0.7.1, 0.7.2
All unaffected versions: 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.2.0, 0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.2.5, 0.3.0, 0.3.1, 0.3.2, 0.3.3, 0.3.4, 0.3.5, 0.3.6, 0.3.7, 0.3.8, 0.3.9, 0.3.10, 0.3.11, 0.3.12, 0.3.13, 0.3.14, 0.3.15, 0.3.16, 0.4.0, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7, 0.6.0, 0.6.1, 0.6.2, 0.6.3, 0.6.4, 0.6.5, 0.6.6, 0.6.7, 0.6.8, 0.6.9, 0.6.10, 0.6.11, 0.6.12, 0.6.13, 0.6.14, 0.6.15, 0.7.3, 0.7.4, 0.7.5