VDB
Sign up
MEDIUM

GHSA-j8cj-hw74-64jv

Hive has Double-free and Use After Free Vulnerabilities

Details

`Drop` implementation for `Hive` did perform free, but so did `Hive::close`, which, at the end of the scope performed `Drop`, therefore triggering double-free.

Additionally, function `Hive::from_handle` was not marked as unsafe, making it, in combination with `as_handle` easy to clone and trigger double-free in safe code or triggering UB when using invalid pointer.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/hivex
Introduced in: 0.2.0Fixed in: 0.2.1

Upgrade hivex to 0.2.1 or newer (ecosystem crates.io).

References