CVE Vulnerabilities

CVE-2017-1000072

Double Free

Published: Jul 17, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected memory locations

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
GravityCreolabs1.0 (including)1.0 (including)

Potential Mitigations

References