Intel

AIKIDO-2025-10256

array-init-cursor is vulnerable to Operation on a Resource after Expiration or Release

Operation on a Resource after Expiration or ReleaseGHSA-67r5-rqwv-9p9q Published Apr 22, 2025

48

Medium Risk

This Affects:

RUSTarray-init-cursor
0.1.0 - 0.2.0
Fixed in 0.2.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Operation on a Resource after Expiration or Release due to unsound handling of types implementing Drop. An attacker can exploit this flaw to trigger undefined behavior, potentially leading to memory corruption through the unintended double execution of a Drop implementation.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

array-init-cursor is vulnerable to Operation on a Resource after Expiration or Release in versions 0.1.0 - 0.2.0.

How to fix this

Upgrade the array-init-cursor library to the patch version.