GHSA-5j8w-r7g8-5472
Dashboard / Vulnerabilities / GHSA-5j8w-r7g8-5472
Summary: Arrow2 allows double free in `safe` code
Details: The struct `Ffi_ArrowArray` implements `#derive(Clone)` that is inconsistent with its custom implementation of `Drop`, resulting in a double free when cloned. Cloning this struct in `safe` results in a segmentation fault, which is unsound. This derive was removed from this struct. All users are advised to either: * bump the patch version of this crate (for versions `v0.7,v0.8,v0.9`), or * migrate to a more recent version of the crate (when using `<0.7`). Doing so elimitates this vulnerability (code no longer compiles).
References: https://github.com/jorgecarleitao/arrow2/issues/880, https://github.com/jorgecarleitao/arrow2, https://rustsec.org/advisories/RUSTSEC-2022-0012.html
Affected packages
Package
Name: arrow2
Purl: pkg:cargo/arrow2
Affected ranges
Type: SEMVER
Events:
