{"id":"CVE-2019-15551","aliases":["GHSA-mm7v-vpv8-xfc3","RUSTSEC-2019-0009"],"url":"https://o3.security/vulnerability/CVE-2019-15551","summary":"Double free in smallvec","details":"Attempting to call grow on a spilled SmallVec with a value equal to the current capacity causes it to free the existing data. This performs a double free immediately and may lead to use-after-free on subsequent accesses to the SmallVec contents. An attacker that controls the value passed to grow may exploit this flaw to obtain memory contents or gain remote code execution.","published":"2019-08-26T15:15:12Z","modified":"2026-07-08T20:15:15.200521Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"smallvec","fixedVersion":"0.6.10"}],"fix":{"url":"https://github.com/servo/rust-smallvec/commit/c20cfa8584e649f00dc0767ab6fad63a3f59a296","label":"servo/rust-smallvec@c20cfa8"},"references":[{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2019-0009.html"},{"type":"FIX","url":"https://github.com/servo/rust-smallvec/issues/148"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15551"},{"type":"WEB","url":"https://github.com/servo/rust-smallvec/issues/149"},{"type":"WEB","url":"https://github.com/servo/rust-smallvec/commit/c20cfa8584e649f00dc0767ab6fad63a3f59a296"},{"type":"WEB","url":"https://github.com/servo/rust-smallvec/commit/f96322b9243405cc82701cc73f1b19313b413ab4"},{"type":"PACKAGE","url":"https://github.com/servo/rust-smallvec"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:15:15.200521Z"}}