Lucene search

K
osvGoogleOSV:GHSA-CV7X-6RC6-PQ5V
HistoryAug 25, 2021 - 8:53 p.m.

Double free in containers

2021-08-2520:53:05
Google
osv.dev
6

0.005 Low

EPSS

Percentile

76.9%

Upon panic in a user-provided function f, fn mutate() & fn mutate2 drops twice a same object.

Affected versions of this crate did not guard against double drop while temporarily duplicating an object’s ownership with ptr::read().

Dropping a same object can result in memory corruption.

The flaw was corrected in version “0.9.11” by fixing the code to abort upon panic.

CPENameOperatorVersion
containerslt0.9.11

0.005 Low

EPSS

Percentile

76.9%

Related for OSV:GHSA-CV7X-6RC6-PQ5V