CVE-2020-35899: Use After Free
Published Dec 31, 2020
·Updated
An issue was discovered in the actix-service crate before 1.0.6 for Rust. The Cell implementation allows obtaining more than one mutable reference to the same data.
Affected Software
2 affected componentsFixes available
actix Actix-service Rust<1.0.6
rust/actix-service<1.0.6
1.0.6
Event History
Dec 31, 2020
CVE Published
via MITRE·08:22 AM
Data Sourced
via MITRE·08:22 AM
Description
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Aug 25, 2021
Advisory Published
via GitHub·08:49 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-35899?
CVE-2020-35899 has been classified as having a medium severity due to the potential for data corruption.
2
How do I fix CVE-2020-35899?
To fix CVE-2020-35899, update the actix-service crate to version 1.0.6 or later.
3
What programming language is affected by CVE-2020-35899?
CVE-2020-35899 affects the Rust programming language.
4
Can CVE-2020-35899 lead to data integrity issues?
Yes, CVE-2020-35899 can lead to data integrity issues by allowing multiple mutable references to the same data.
5
Is CVE-2020-35899 present in earlier versions of actix-service?
Yes, CVE-2020-35899 is present in versions of actix-service prior to 1.0.6.