Critical severity9.8NVD Advisory· Published Mar 5, 2021· Updated Jun 17, 2026
CVE-2021-28032
CVE-2021-28032
Description
An issue was discovered in the nano_arena crate before 0.5.2 for Rust. There is an aliasing violation in split_at because two mutable references can exist for the same element, if Borrow behaves in certain ways. This can have a resultant out-of-bounds write or use-after-free.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nano_arenacrates.io | < 0.5.2 | 0.5.2 |
Affected products
3- Rust/nano_arenadescription
- cpe:2.3:a:nano_arena_project:nano_arena:*:*:*:*:*:rust:*:*Range: <0.5.2
Patches
Vulnerability mechanics
References
5- rustsec.org/advisories/RUSTSEC-2021-0031.htmlnvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-wp34-mqw5-jj85ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-28032ghsaADVISORY
- github.com/bennetthardwick/nano-arena/commit/6b83f9d0708337a9f8b709c1624a8587021ceba2ghsaWEB
- github.com/bennetthardwick/nano-arena/issues/1ghsaWEB
News mentions
0No linked articles in our index yet.