Intel

AIKIDO-2025-10075

sdd is vulnerable to Use after free

Use after free Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

47

Medium Risk

This Affects:

Rustsdd
2.0.0 - 3.0.6
Fixed in 3.0.7

TL;DR

Affected versions of this package are affected by a design flaw arising when the last thread-local variable is dropped. An attacker can exploit this use-after-free vulnerability to crash the server or leak arbitrary memory contents.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

sdd is vulnerable to Use after free in versions 2.0.0 - 3.0.6.

How to fix this

Upgrade the sdd library to the patch version.