VDB
Sign up
—

RUSTSEC-2026-0131

Double-free in `Chomp::inner()`

Details

`Chomp::inner()` uses `std::ptr::read_unaligned` to move out the value from a raw pointer. If the original value is an owned type (e.g. `Box`), calling `inner()` moves out the ownership, but the original variable will still be dropped at the end of its scope. This causes the same heap memory to be freed twice, resulting in a double-free and undefined behavior.

This can be triggered through safe public APIs — `Chomp::new()` and `Chomp::inner()` — with no `unsafe` required from the caller.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/bitchomp
Introduced in: 0.0.0-0

No fixed version published yet for bitchomp. Pin to a known-safe version or switch to an alternative.

References