Intel

AIKIDO-2025-10701

nixl is vulnerable to Use After Free

Use After Free Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 10, 2025

20

Low Risk

This Affects:

PYTHONnixl
0.1.0 - 0.6.0
Fixed in 0.6.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a Use-After-Free after disconnect due to improper management of the transfer request ownership. An attacker could potentially exploit this vulnerability by triggering an error condition that causes the agent to prematurely free a request object, resulting in the client application using a dangling pointer. This use of a freed resource could result in a crash or data corruption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

nixl is vulnerable to Use After Free in versions 0.1.0 - 0.6.0.

How to fix this

Upgrade the nixl library to the patch version.