CVE-2021-31162

Severity
9.8CRITICAL
EPSS
0.7%
top 27.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 24

Description

In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDrust-lang/rust1.48.01.52.0
Debianrustc< 1.53.0+dfsg1-1+2

Also affects: Fedora 32, 33, 34

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fjcw-72x2-rmmv: In the standard library in Rust before 12022-05-24
OSV
CVE-2021-31162: In the standard library in Rust before 12021-04-14
CVEList
CVE-2021-31162: In the standard library in Rust before 12021-04-14

📋Vendor Advisories

3
Microsoft
In the standard library in Rust before 1.52.0 a double free can occur in the Vec::from_iter function if freeing the element panics.2021-04-13
Red Hat
rust: double free in Vec::from_iter function if freeing the element panics2021-03-28
Debian
CVE-2021-31162: rustc - In the standard library in Rust before 1.52.0, a double free can occur in the Ve...2021
CVE-2021-31162 (CRITICAL CVSS 9.8) | In the standard library in Rust bef | cvebase.io