
Cloud Vulnerability DB
A community-led vulnerabilities database
BitVecCore::clear drops every occupied element with drop_in_place and only
afterwards clears the occupancy bits and resets len. If an element's Drop
panics, those metadata updates are skipped, so the slot of the already-dropped
element stays marked as occupied. BitVecCore::drop calls clear() again,
visits the same slot, and drops the element a second time — a double-free /
use-after-free reachable from safe Rust.
Reachable via the public StableVec::clear and ExternStableVec::clear, which
delegate to BitVecCore::clear.
Drop.
Reachable entirely from safe Rust via catch_unwind with element types whoseDrop can panic. Confirmed under AddressSanitizer on 0.4.2.
Fixed in stable-vec 0.4.3 by removing each element via remove_at, which
clears the occupancy bit before taking the value out.
Release 0.4.3 also fixes several other panic-safety issues found by the
maintainer; see GHSA-mr2v-63pc-gmr4
and the 0.4.3 changelog for the full list.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."