Vulnerability record · CVE-2021-29922 · published 7 August 2021
CVE-2021-29922: Rust-lang rust vulnerability
Rust Lang · Rust
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.
Description
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://defcon.org/html/defcon-29/dc-29-speakers.html#kaoudis | Third Party Advisory |
| https://doc.rust-lang.org/beta/std/net/struct.Ipv4Addr.html | Vendor Advisory |
| https://github.com/rust-lang/rust/issues/83648 | ExploitIssue TrackingPatchThird Party Advisory |
| https://github.com/rust-lang/rust/pull/83652 | PatchThird Party Advisory |
| https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-015.md | ExploitThird Party Advisory |
| https://security.gentoo.org/glsa/202210-09 | Third Party Advisory |
| https://defcon.org/html/defcon-29/dc-29-speakers.html#kaoudis | Third Party Advisory |
| https://doc.rust-lang.org/beta/std/net/struct.Ipv4Addr.html | Vendor Advisory |
| https://github.com/rust-lang/rust/issues/83648 | ExploitIssue TrackingPatchThird Party Advisory |
| https://github.com/rust-lang/rust/pull/83652 | PatchThird Party Advisory |
| https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-015.md | ExploitThird Party Advisory |
| https://security.gentoo.org/glsa/202210-09 | Third Party Advisory |
Track CVE-2021-29922 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-29922), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.