Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-36318

Опубликовано: 07 дек. 2020
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or double free.

Отчет

VecDeque::make_contiguous is not considered stable is versions of rust prior to 1:48. As a result, it should not be used as shipped in Red Hat Enterprise Linux versions 8.3 and older.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9rustNot affected
Red Hat Developer Toolsrust-toolset-1.49FixedRHSA-2021:224303.06.2021
Red Hat Developer Toolsrust-toolset-1.49-rustFixedRHSA-2021:224303.06.2021
Red Hat Enterprise Linux 8rust-toolsetFixedRHSA-2021:193518.05.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1949192rust: use-after-free or double free in VecDeque::make_contiguous

EPSS

Процентиль: 57%
0.00356
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 5 лет назад

In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or double free.

CVSS3: 9.8
nvd
почти 5 лет назад

In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or double free.

CVSS3: 9.8
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 9.8
debian
почти 5 лет назад

In the standard library in Rust before 1.49.0, VecDeque::make_contiguo ...

github
больше 3 лет назад

In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or double free.

EPSS

Процентиль: 57%
0.00356
Низкий

9.8 Critical

CVSS3