RUSTSEC-2026-0205

Source
https://rustsec.org/advisories/RUSTSEC-2026-0205
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0205.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0205
Published
2026-07-06T12:00:00Z
Modified
2026-07-07T09:30:04.274635773Z
Summary
`Array::insert` violates exception safety if compare function panics, leading to potential Double-Free
Details

In affected versions of this crate, Array::insert is not exception safe. In the UPSERT path, key and value's snapshot is written to self.data_block, and after the insertion is completed, key and value are mem::forget in order to prevent double free. However, during the insertion, K::compare is invoked, which is a user-provided method. If user deliberately call panic in this function, during unwinding, the destructors of key, value, and self will all be called (since the mem::forget has not been called yet), leading to Double Free. Similar issues happens in the !UPSERT path.

The soundness issue was fixed in version 3.8.4 by using ManuallyDrop instead of mem::forget, and separating fallible code from infallible code during a node split - insert = inserttry -> insertunchecked.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / scc

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
3.8.4

Ecosystem specific

{
    "affects": {
        "os": [],
        "functions": [],
        "arch": []
    },
    "affected_functions": null
}

Database specific

source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0205.json"
categories
[]
cvss
null
informational
"unsound"