{"id":"CVE-2021-28032","aliases":["RUSTSEC-2021-0031"],"url":"https://o3.security/vulnerability/CVE-2021-28032","summary":"Use after free in nano_arena","details":"Affected versions of this crate assumed that Borrow<Idx> was guaranteed to return the same value on .borrow(). The borrowed index value was used to retrieve a mutable reference to a value.\n\nIf the Borrow<Idx> implementation returned a different index, the split arena would allow retrieving the index as a mutable reference creating two mutable references to the same element. This violates Rust's aliasing rules and allows for memory safety issues such as writing out of bounds and use-after-frees.\n\nThe flaw was corrected in commit `6b83f9d` by storing the .borrow() value in a temporary variable.","published":"2021-08-25T20:52:00Z","modified":"2023-11-08T04:05:27.788398Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"crates.io","name":"nano_arena","fixedVersion":"0.5.2"}],"fix":{"url":"https://github.com/bennetthardwick/nano-arena/commit/6b83f9d0708337a9f8b709c1624a8587021ceba2","label":"bennetthardwick/nano-arena@6b83f9d"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28032"},{"type":"WEB","url":"https://github.com/bennetthardwick/nano-arena/issues/1"},{"type":"WEB","url":"https://github.com/bennetthardwick/nano-arena/commit/6b83f9d0708337a9f8b709c1624a8587021ceba2"},{"type":"PACKAGE","url":"https://github.com/bennetthardwick/nano-arena"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2021-0031.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:05:27.788398Z"}}