mediumVulnerability
GHSA-j8cj-hw74-64jv
`Drop` implementation for `Hive` did perform free, but so did `Hive::close`, which, at the end of the scope performed `Drop`, therefore triggering double-free. Additionally, function `Hive::from_handle` was not marked as unsafe, making it, in combination with `as_handle` easy to clone and trigger double-free in safe code or triggering UB when using invalid pointer.
Properties
- ghsa_id
- GHSA-j8cj-hw74-64jv
- severity
- medium
- summary
- Hive has Double-free and Use After Free Vulnerabilities
- cve_id
- GHSA-j8cj-hw74-64jv
- is_ghsa_only
- true
- ghsa_published
- 2026-02-28T02:48:45Z
- source_url
- https://github.com/advisories/GHSA-j8cj-hw74-64jv
- ghsa_updated
- 2026-02-28T02:48:47Z
Related Entities (4)
AFFECTS (1)
→[Software]rust/hivex
HAS_WEAKNESS (2)
→[Weakness]Use After Free
→[Weakness]Double Free
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph