GHSA-f85w-wvc7-crwc

Suggest an improvement
Source
https://github.com/advisories/GHSA-f85w-wvc7-crwc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-f85w-wvc7-crwc/GHSA-f85w-wvc7-crwc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f85w-wvc7-crwc
Aliases
Downstream
CGA (8)
Published
2023-01-20T21:54:22Z
Modified
2026-09-10T03:49:51Z
Summary
bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()`
Details

In affected versions of this crate, the lifetime of the iterator produced by Vec::into_iter() is not constrained to the lifetime of the Bump that allocated the vector's memory. Using the iterator after the Bump is dropped causes use-after-free accesses.

The following example demonstrates memory corruption arising from a misuse of this unsoundness.

use bumpalo::{collections::Vec, Bump};

fn main() {
    let bump = Bump::new();
    let mut vec = Vec::new_in(&bump);
    vec.extend([0x01u8; 32]);
    let into_iter = vec.into_iter();
    drop(bump);

    for _ in 0..100 {
        let reuse_bump = Bump::new();
        let _reuse_alloc = reuse_bump.alloc([0x41u8; 10]);
    }

    for x in into_iter {
        print!("0x{:02x} ", x);
    }
    println!();
}

The issue was corrected in version 3.11.1 by adding a lifetime to the IntoIter type, and updating the signature of Vec::into_iter() to constrain this lifetime.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-01-20T21:54:22Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

crates.io / bumpalo

Package

Name
bumpalo
View open source insights on deps.dev
Purl
pkg:cargo/bumpalo

Affected ranges

Type
SEMVER
Events
Introduced
1.1.0
Fixed
3.11.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-f85w-wvc7-crwc/GHSA-f85w-wvc7-crwc.json"