{"id":"GHSA-jh37-772x-4hpw","summary":"Double free in algorithmica","details":"An issue was discovered in the algorithmica crate through 2021-03-07 for Rust. In the affected versions of this crate, `merge_sort::merge()` wildly duplicates and drops ownership of `T` without guarding against double-free. Due to such implementation, simply invoking `merge_sort::merge()` on `Vec\u003cT: Drop\u003e` can cause **double free** bugs.\n","aliases":["CVE-2021-31996","RUSTSEC-2021-0053"],"modified":"2023-11-08T04:05:51.884944Z","published":"2021-08-25T21:01:52Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-415"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-05-25T20:52:19Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-31996"},{"type":"WEB","url":"https://github.com/AbrarNitk/algorithmica/issues/1"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2021-0053.html"}],"affected":[{"package":{"name":"algorithmica","ecosystem":"crates.io","purl":"pkg:cargo/algorithmica"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.1.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-jh37-772x-4hpw/GHSA-jh37-772x-4hpw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}