CVE-2020-36318: Rust-Lang Rust
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or double free.
Affected products
- Rust-Lang Rust: from 1.48.0, before 1.49.0 (fixed in 1.49.0)
Published 2021-04-11. Last modified 2026-06-17.