RUSTSEC-2024-0018

    Dashboard / Vulnerabilities / RUSTSEC-2024-0018

    RUSTSEC-2024-0018

    Published: 27 Feb 2024Last Modified: 11 Apr 2024

    Summary: ObjectPool creates uninitialized memory when freeing objects

    Details: As of version 0.6.0, the ObjectPool explicitly creates an uninitialized instance of its type parameter when it attempts to free an object, and swaps it into the storage. This causes instant undefined behavior due to reading the uninitialized memory in order to write it to the pool storage. Extremely basic usage of the crate can trigger this issue, e.g. this code from a doctest: ```rust use crayon::prelude::*; application::oneshot().unwrap(); let mut params = MeshParams::default(); let mesh = video::create_mesh(params, None).unwrap(); // Deletes the mesh object. video::delete_mesh(mesh); // <-- UB ``` The Clippy warning for this code was silenced in commit c2fde19caf6149d91faa504263f0bc5cafc35de5. Discovered via https://asan.saethlin.dev/ub?crate=crayon&version=0.7.1

    Affected packages

    Package

    Name: crayon

    Purl: pkg:cargo/crayon

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.6.0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2024-0018 | CVE-DB