CVE-2023-53160

The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sequoia-pgp:sequoia-openpgp:*:*:*:*:*:rust:*:*
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:*:*:*:*:*:rust:*:*
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:*:*:*:*:*:rust:*:*

History

06 Aug 2025, 21:15

Type Values Removed Values Added
First Time Sequoia-pgp
Sequoia-pgp sequoia-openpgp
CPE cpe:2.3:a:sequoia-pgp:sequoia-openpgp:*:*:*:*:*:rust:*:*
References () https://crates.io/crates/sequoia-openpgp - () https://crates.io/crates/sequoia-openpgp - Product
References () https://github.com/advisories/GHSA-25mx-8f3v-8wh7 - () https://github.com/advisories/GHSA-25mx-8f3v-8wh7 - Third Party Advisory
References () https://lists.sequoia-pgp.org/hyperkitty/list/announce@lists.sequoia-pgp.org/thread/SN2E3QRT4DMQ5JNEK6VIN6DJ5SH766DI/ - () https://lists.sequoia-pgp.org/hyperkitty/list/announce@lists.sequoia-pgp.org/thread/SN2E3QRT4DMQ5JNEK6VIN6DJ5SH766DI/ - Patch
References () https://rustsec.org/advisories/RUSTSEC-2023-0038.html - () https://rustsec.org/advisories/RUSTSEC-2023-0038.html - Third Party Advisory

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) El paquete sequoia-openpgp para Rust anterior a 1.16.0 permite el acceso a matrices fuera de los límites y un pánico.

28 Jul 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-28 03:15

Updated : 2025-08-06 21:15


NVD link : CVE-2023-53160

Mitre link : CVE-2023-53160

CVE.ORG link : CVE-2023-53160


JSON object : View

Products Affected

sequoia-pgp

  • sequoia-openpgp
CWE
CWE-125

Out-of-bounds Read