Intel

AIKIDO-2024-10450

mimalloc is vulnerable to Access of Uninitialized Pointer

Access of Uninitialized Pointer Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 19, 2024

63

Medium Risk

This Affects:

rustmimalloc
0.1.26 - 0.1.38
Fixed in 0.1.39
Are you affected? Scan for Free

TL;DR

Affected versions of this package may cause access to an uninitialized pointer due to changes in the allocator's logic, which avoided aligned allocation functions for performance reasons. This flaw can be exploited by attackers to cause memory misalignment issues.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

mimalloc is vulnerable to Access of Uninitialized Pointer in versions 0.1.26 - 0.1.38.

How to fix this

Upgrade the mimalloc library to the patch version.