CVE-2020-25576: Rust-Random Rand
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
Affected products
- Rust-Random Rand: before 0.4.2 (fixed in 0.4.2)
Published 2020-09-14. Last modified 2026-08-19.