OSV 1.4.0 · github-reviewed · 修改于 2026-05-20 03:39
发布时间
2026-05-20 03:39
GitHub 审查时间
2026-05-20 03:39
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/05/GHSA-q8x8-jrhj-fh9p/GHSA-q8x8-jrhj-fh9p.json
Diesel allows to register custom aggregate SQL functions for SQLite via the SqliteAggregate interface.
To store an instance of the custom aggregate processor Diesel relied on the sqlite3_aggregate_context function provided by sqlite. This function doesn't provide any guarantees about alignment of the returned allocation, which in turn can lead to problems if the type implementing requires a special alignment, e.g. via a custom #[align(x)] attribute on the type implementing this trait. This affects any user of SqliteAggregate that registers the custom aggregate function with an SQLite connection, while using a non-standard alignment on the type implementing this trait.
The preferred mitigation to the outlined problem is to update to a Diesel version 2.3.8 or newer, which includes fixes for the problem.
Diesel now allocates the corresponding memory on Rust side to get a correctly aligned allocation.