CVE-2021-27378 PUBLISHED

An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.

EPSS 0.47% · 64.3th percentile

Risk Scores

EPSS Score
0.47%
64.3th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10rust-rand-core0, 0.6.4-2
Ubuntu:22.04:LTSrust-rand-core0, 0.5.1-1, 0.6.3-2
Ubuntu:24.04:LTSrust-rand-core0.6.4-1, 0, 0.6.3-2
Ubuntu:20.04:LTSrust-rand-core0, 0.3.0-1, 0.5.1-1

Timeline

References

Open in Interactive Console →