{"id":"GHSA-j8cj-hw74-64jv","summary":"Hive has Double-free and Use After Free Vulnerabilities","details":"`Drop` implementation for `Hive` did perform free, but so did `Hive::close`, which, at the end of the scope performed `Drop`, therefore triggering double-free.\n\nAdditionally, function `Hive::from_handle` was not marked as unsafe, making it, in combination with `as_handle` easy to clone and trigger double-free in safe code or triggering UB when using invalid pointer.","aliases":["RUSTSEC-2026-0029"],"modified":"2026-03-01T06:11:19.337988Z","published":"2026-02-28T02:48:45Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-28T02:48:45Z","nvd_published_at":null,"cwe_ids":["CWE-415","CWE-416"]},"references":[{"type":"WEB","url":"https://codeberg.org/1millibyte/toolsnt/commit/f4c7a0d1fc4a08ce40bb76e447a69a6f383a916e"},{"type":"WEB","url":"https://codeberg.org/1millibyte/toolsnt/issues/18"},{"type":"WEB","url":"https://docs.rs/crate/hivex"},{"type":"WEB","url":"https://docs.rs/crate/hivex/0.2.1/source"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0029.html"}],"affected":[{"package":{"name":"hivex","ecosystem":"crates.io","purl":"pkg:cargo/hivex"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.2.0"},{"fixed":"0.2.1"}]}],"versions":["0.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-j8cj-hw74-64jv/GHSA-j8cj-hw74-64jv.json"}}],"schema_version":"1.9.0"}