VDB
Sign up
HIGH

GHSA-5j8w-r7g8-5472

Arrow2 allows double free in `safe` code

Details

The struct `Ffi_ArrowArray` implements `#derive(Clone)` that is inconsistent with its custom implementation of `Drop`, resulting in a double free when cloned.

Cloning this struct in `safe` results in a segmentation fault, which is unsound.

This derive was removed from this struct. All users are advised to either: * bump the patch version of this crate (for versions `v0.7,v0.8,v0.9`), or * migrate to a more recent version of the crate (when using `<0.7`).

Doing so elimitates this vulnerability (code no longer compiles).

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/arrow2
Introduced in: 0Fixed in: 0.7.1

Upgrade arrow2 to 0.7.1 or newer (ecosystem crates.io).

crates.io/arrow2
Introduced in: 0.8.0Fixed in: 0.8.2

Upgrade arrow2 to 0.8.2 or newer (ecosystem crates.io).

crates.io/arrow2
Introduced in: 0.9.0Fixed in: 0.9.2

Upgrade arrow2 to 0.9.2 or newer (ecosystem crates.io).

References