rkyv is vulnerable to Double Free
35
Low Risk
Affected versions of rkyv contain a panic-safety issue in InlineVec::clear() and SerVec::clear(). If an element’s Drop implementation panics during cleanup, the container length is not updated correctly, causing subsequent calls to clear already-freed elements and potentially resulting in a double free or memory corruption.
You are affected if you are using a version that falls within the vulnerable range.
rkyv is vulnerable to Double Free in versions 0.8.0 - 0.8.15.
Upgrade the rkyv library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant