RUSTSEC-2026-0255

Source
https://rustsec.org/advisories/RUSTSEC-2026-0255
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0255.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0255
Published
2026-08-11T12:00:00Z
Modified
2026-08-12T10:30:03.078996208Z
Summary
Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)
Details

Several methods in sized-chunks drop elements before updating the length/boundary metadata. If an element's Drop panics during the drop, the metadata update is skipped, so the container still treats the already-dropped elements as live. When the container's own Drop runs, those elements are visited again — a use-after-free / double-free reachable from safe Rust.

The RingBuffer methods require the ringbuffer feature. This is distinct from RUSTSEC-2020-0041 (Chunk::clone / insert_from, fixed in 0.6.3); the methods here are still affected in 0.7.0. The repository is archived with issues/PRs disabled and no fix available.

Impact

  • CWE-415 (Double Free): the same allocation is freed twice.
  • CWE-416 (Use-After-Free): a freed allocation is accessed during a repeated Drop.

Reachable entirely from safe Rust via catch_unwind with element types whose Drop can panic.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / sized-chunks

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0

Ecosystem specific

{
    "affects": {
        "os": [],
        "functions": [
            "sized_chunks::Chunk::clear",
            "sized_chunks::Chunk::drop_left",
            "sized_chunks::Chunk::drop_right",
            "sized_chunks::InlineArray::clear",
            "sized_chunks::RingBuffer::clear",
            "sized_chunks::RingBuffer::drop_left",
            "sized_chunks::RingBuffer::drop_right"
        ],
        "arch": []
    },
    "affected_functions": null
}

Database specific

categories
[
    "memory-corruption"
]
informational
"unsound"
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0255.json"
cvss
null