aligned_box is vulnerable to Use-After-Free
36
Low Risk
A security vulnerability in AlignedBox<[T]> can cause a double free or use-after-free when shrinking a buffer containing a type with a panicking Drop implementation. If Drop panics while destroying removed elements, the buffer update is skipped, causing the destructor to access already-destroyed elements.
You are affected if you are using a version that falls within the vulnerable range and you are using aligned_box::AlignedBox::realloc_with_default.
aligned_box is vulnerable to Use-After-Free in versions 0.0.1 - 0.3.0.
Upgrade the aligned_box library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.