Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🦀 crates.io
Not in CISA KEV

GHSA-5j8w-r7g8-5472 arrow2

GHSA-5j8w-r7g8-5472 is a security vulnerability in arrow2. A fix is available for arrow2 — see the affected versions and patch details below.

Arrow2 allows double free in `safe` code

Also known asRUSTSEC-2022-0012
Published
Jun 16, 2022
Updated
Nov 8, 2023
Affected
3 pkgs
Patched
3 / 3
Exploits
None indexed
Exploitation data as of Nov 8, 2023 · OSV.dev, FIRST.org (EPSS)

Real-World Exposure

3 pkgs affected
🦀arrow2🦀arrow2🦀arrow2

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects crates.io packages — download data is not available via public APIs for these ecosystems.

Description

The struct Ffi_ArrowArray implements #derive(Clone) that is inconsistent with its custom implementation of Drop, resulting in a double free when cloned.

Cloning this struct in safe results in a segmentation fault, which is unsound.

This derive was removed from this struct. All users are advised to either:

  • bump the patch version of this crate (for versions v0.7,v0.8,v0.9), or
  • migrate to a more recent version of the crate (when using <0.7).

Doing so elimitates this vulnerability (code no longer compiles).

Affected Packages

3 total 3 fixed
EcosystemPackageVulnerable rangeFix
🦀crates.ioarrow2all versions0.7.1cargo update -p arrow2 --precise 0.7.1
🦀crates.ioarrow20.8.0&&< 0.8.20.8.2cargo update -p arrow2 --precise 0.8.2
🦀crates.ioarrow20.9.0&&< 0.9.20.9.2cargo update -p arrow2 --precise 0.9.2

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for arrow2, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update arrow2 to 0.7.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-5j8w-r7g8-5472 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like GHSA-5j8w-r7g8-5472 can be triaged on real exposure rather than presence alone.

Tailored to GHSA-5j8w-r7g8-5472. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

The struct `Ffi_ArrowArray` implements `#derive(Clone)` that is inconsistent with its custom implementation of `Drop`, resulting in a double free when cloned. Cloning this struct in `safe` results in a segmentation fault, which is unsound. This derive was removed from this struct. All users are advised to either: * bump the patch version of this crate (for versions `v0.7,v0.8,v0.9`), or * migrate to a more recent version of the crate (when using `<0.7`). Doing so elimitates this vulnerability (code no longer compiles).
O3 Security · Impact-Aware SCA

Is GHSA-5j8w-r7g8-5472 in your dependencies?

O3 Security finds GHSA-5j8w-r7g8-5472 across crates.io dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.

GHSA-5j8w-r7g8-5472: arrow2 | O3 Security