CVE-2020-35906: Use After Free
Published Dec 31, 2020
·Updated
An issue was discovered in the futures-task crate before 0.3.6 for Rust. futurestask::waker may cause a use-after-free in a non-static type situation.
Affected Software
2 affected components
rust-lang Futures-task Rust<0.3.6
rust-lang Futures-task Rust>=0.2.1<0.3.6
Remediation
Patch Available
Event History
Dec 31, 2020
CVE Published
via MITRE·08:21 AM
Data Sourced
via MITRE·08:21 AM
Description
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-35906.
2
What is the title of this vulnerability?
The title of this vulnerability is 'An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situation.'
3
What is the severity of CVE-2020-35906?
The severity of CVE-2020-35906 is high with a CVSS score of 7.8.
4
Which software is affected by CVE-2020-35906?
The Rust-lang Futures-task crate versions up to exclusive 0.3.6 are affected by CVE-2020-35906.
5
How can I fix the vulnerability CVE-2020-35906?
To fix the vulnerability CVE-2020-35906, update the affected software to a version beyond 0.3.6.