Lucene search

K
osvGoogleOSV:GHSA-68P4-PJPF-XWCQ
HistoryMay 24, 2022 - 5:41 p.m.

insert_slice_clone can double drop if Clone panics.

2022-05-2417:41:47
Google
osv.dev
5

0.001 Low

EPSS

Percentile

43.5%

Affected versions of this crate used ptr::copy when inserting into the middle of a Vec. When ownership was temporarily duplicated during this copy, it calls the clone method of a user provided element.

This issue can result in an element being double-freed if the clone call panics.

Commit 20cb73d fixed this issue by adding a set_len(0) call before operating on the vector to avoid dropping the elements during a panic.

CPENameOperatorVersion
qwutilslt0.3.1

0.001 Low

EPSS

Percentile

43.5%

Related for OSV:GHSA-68P4-PJPF-XWCQ