{"id":"GHSA-mm7v-vpv8-xfc3","summary":"Double free in smallvec","details":"Attempting to call grow on a spilled SmallVec with a value equal to the current capacity causes it to free the existing data. This performs a double free immediately and may lead to use-after-free on subsequent accesses to the SmallVec contents. An attacker that controls the value passed to grow may exploit this flaw to obtain memory contents or gain remote code execution.","aliases":["CVE-2019-15551","RUSTSEC-2019-0009"],"modified":"2023-11-08T04:01:14.162214Z","published":"2021-08-25T20:44:59Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-415"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-08-19T21:22:23Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15551"},{"type":"WEB","url":"https://github.com/servo/rust-smallvec/issues/148"},{"type":"WEB","url":"https://github.com/servo/rust-smallvec/issues/149"},{"type":"WEB","url":"https://github.com/servo/rust-smallvec/commit/c20cfa8584e649f00dc0767ab6fad63a3f59a296"},{"type":"WEB","url":"https://github.com/servo/rust-smallvec/commit/f96322b9243405cc82701cc73f1b19313b413ab4"},{"type":"PACKAGE","url":"https://github.com/servo/rust-smallvec"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2019-0009.html"}],"affected":[{"package":{"name":"smallvec","ecosystem":"crates.io","purl":"pkg:cargo/smallvec"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.6.5"},{"fixed":"0.6.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-mm7v-vpv8-xfc3/GHSA-mm7v-vpv8-xfc3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}