Merge pull request #665 from JOE1994/0083-array-tools

array-tools: `FixedCapacityDequeLike::clone()` can cause dropping uninitialized memory
This commit is contained in:
Sergey "Shnatsel" Davidoff
2021-01-30 19:12:48 +01:00
committed by GitHub

View File

@@ -0,0 +1,15 @@
```toml
[advisory]
id = "RUSTSEC-0000-0000"
package = "array-tools"
date = "2020-12-31"
url = "https://github.com/L117/array-tools/issues/2"
categories = ["memory-corruption"]
[versions]
patched = []
```
# `FixedCapacityDequeLike::clone()` can cause dropping uninitialized memory
Affected versions of this crate don't guard against panics, so that partially uninitialized buffer is dropped when user-provided `T::clone()` panics in `FixedCapacityDequeLike<T, A>::clone()`. This causes memory corruption.