Vulnerability DatabaseGHSA-3632-54q8-m96x

GHSA-3632-54q8-m96x
Rust vulnerability analysis and mitigation

Overview

The arenavec crate (version <= 0.1.1) contains multiple critical memory corruption vulnerabilities that can be triggered through safe APIs. The vulnerabilities were discovered and reported in August 2025, with an official advisory issued on September 1, 2025. The affected package is a Rust crate that provides arena-based vector implementations (RustSec Advisory).

Technical details

The vulnerabilities manifest in three distinct ways: 1) The arenavec::common::AllocHandle trait allows returning raw pointers through its methods without being marked as unsafe, potentially leading to arbitrary memory access when these pointers are dereferenced in safe APIs like SliceVec::push. 2) The SliceVec::reserve implementation can cause a mismatch between the reported capacity and actual allocated memory due to incorrect behavior in allocate_inner, resulting in heap buffer overflows. 3) The SliceVec::split_off method can create duplicate ownership of elements that implement the Drop trait, leading to double-free violations when both copies are deallocated (GitHub Issue 4, GitHub Issue 5, GitHub Issue 6).

Impact

The vulnerabilities can lead to severe memory safety violations including arbitrary memory access, heap buffer overflows, and double-free violations. These issues can result in program crashes, memory corruption, and potential security breaches in applications using the affected versions of the arenavec crate (RustSec Advisory).

Mitigation and workarounds

Currently, there are no patched versions available for these vulnerabilities. Users are advised to avoid using the arenavec crate in its current form, as the issues affect core functionality and can be triggered through safe APIs (RustSec Advisory).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22257HIGH8.8
  • RustRust
  • salvo
NoYesJan 08, 2026
CVE-2026-22698HIGH8.7
  • RustRust
  • sm2
NoNoJan 10, 2026
CVE-2026-22699HIGH7.5
  • RustRust
  • sm2
NoNoJan 10, 2026
GHSA-g59m-gf8j-gjf5LOW3.7
  • RustRust
  • aws-sdk-eventbridge
NoYesJan 08, 2026
GHSA-585q-cm62-757jLOW2
  • RustRust
  • mnl
NoNoJan 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management