CVE-2021-32810 - log back

CVE-2021-32810 edited at 12 Oct 2021 14:42:24
References
https://www.mozilla.org/security/advisories/mfsa2021-43/
+ https://www.mozilla.org/security/advisories/mfsa2021-47/
https://bugzilla.mozilla.org/show_bug.cgi?id=1729813
https://github.com/crossbeam-rs/crossbeam/security/advisories/GHSA-pqqp-xmhj-wgcw
CVE-2021-32810 created at 05 Oct 2021 13:06:06
Severity
+ Medium
Remote
+ Remote
Type
+ Information disclosure
Description
+ In the crossbeam crate, one or more tasks in the worker queue could have been be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this could have caused a double free and a memory leak.
References
+ https://www.mozilla.org/security/advisories/mfsa2021-43/
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1729813
+ https://github.com/crossbeam-rs/crossbeam/security/advisories/GHSA-pqqp-xmhj-wgcw
Notes