PT-2024-40279 · Mimalloc · Mimalloc

Published

2024-11-12

·

Updated

2024-11-12

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions: No specific software name or version is mentioned, however, the issue concerns a crate that depends on the mimalloc allocator.
Description: The issue arises from a change in the mimalloc allocator's logic, which broke a promise regarding alignments. This caused the crate to return memory with incorrect alignment for certain allocations, particularly those with large alignments. The problem was resolved by using aligned allocation functions.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-G23H-7VF9-XC25

Affected Products

Mimalloc