HistoryEditJSON (OSV)

CVE-2015-20001

Panic safety violation in BinaryHeap

Reported
Issued
Package
std
Type
Vulnerability
Categories
References
Patched
  • >=1.2.0
Unaffected
  • <1.0.0

Description

In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is left in an inconsistent state when the comparison of generic elements inside sift_up or sift_down_range panics. This bug leads to a drop of zeroed memory as an arbitrary type, which can result in a memory safety violation.

Advisory available under CC0-1.0 license.