VYPR
Critical severityNVD Advisory· Published Apr 7, 2021· Updated Aug 3, 2024

CVE-2021-30456

CVE-2021-30456

Description

An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in get_or_insert upon a panic of a user-provided f function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A double-free vulnerability in the id-map Rust crate's get_or_insert function can occur when the user-provided closure panics.

Vulnerability

The get_or_insert function in the id-map crate (all versions up to 2021-02-26) contains a double-free vulnerability. When a user-provided closure f panics after space has been reserved for the new value, the previously dropped values in the map can be freed again, leading to a double free [1][2][3].

Exploitation

An attacker can trigger this vulnerability by providing a closure that panics during the get_or_insert call. No special privileges are required; the attacker only needs to be able to call the function with a panicking closure. The panic can be induced by various means, such as memory exhaustion or a deliberate panic inside the closure [1].

Impact

Successful exploitation results in a double free, which can cause memory corruption. This may lead to arbitrary code execution or denial of service, depending on how the application uses the id-map crate. The vulnerability is classified as memory corruption [3].

Mitigation

As of the RustSec advisory (RUSTSEC-2021-0052), no patched version of the id-map crate exists [3]. The crate appears unmaintained. Users should avoid using the get_or_insert function with untrusted closures or consider migrating to a different map implementation that is actively maintained. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
id-mapcrates.io
<= 0.2.1

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.