{"id":"GHSA-wp34-mqw5-jj85","summary":"Use after free in nano_arena","details":"Affected versions of this crate assumed that Borrow\u003cIdx\u003e was guaranteed to return the same value on .borrow(). The borrowed index value was used to retrieve a mutable reference to a value.\n\nIf the Borrow\u003cIdx\u003e implementation returned a different index, the split arena would allow retrieving the index as a mutable reference creating two mutable references to the same element. This violates Rust's aliasing rules and allows for memory safety issues such as writing out of bounds and use-after-frees.\n\nThe flaw was corrected in commit `6b83f9d` by storing the .borrow() value in a temporary variable.","aliases":["CVE-2021-28032","RUSTSEC-2021-0031"],"modified":"2023-11-08T04:05:27.788398Z","published":"2021-08-25T20:52:00Z","database_specific":{"cwe_ids":["CWE-416"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-08-19T17:23:52Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28032"},{"type":"WEB","url":"https://github.com/bennetthardwick/nano-arena/issues/1"},{"type":"WEB","url":"https://github.com/bennetthardwick/nano-arena/commit/6b83f9d0708337a9f8b709c1624a8587021ceba2"},{"type":"PACKAGE","url":"https://github.com/bennetthardwick/nano-arena"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2021-0031.html"}],"affected":[{"package":{"name":"nano_arena","ecosystem":"crates.io","purl":"pkg:cargo/nano_arena"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-wp34-mqw5-jj85/GHSA-wp34-mqw5-jj85.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}