RUSTSEC-2026-0255
Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)
상세
Several methods in `sized-chunks` drop elements before updating the length/boundary metadata. If an element's `Drop` panics during the drop, the metadata update is skipped, so the container still treats the already-dropped elements as live. When the container's own `Drop` runs, those elements are visited again — a use-after-free / double-free reachable from safe Rust.
The `RingBuffer` methods require the `ringbuffer` feature. This is distinct from RUSTSEC-2020-0041 (`Chunk::clone` / `insert_from`, fixed in 0.6.3); the methods here are still affected in 0.7.0. The repository is archived with issues/PRs disabled and no fix available.
## Impact
- **CWE-415 (Double Free):** the same allocation is freed twice. - **CWE-416 (Use-After-Free):** a freed allocation is accessed during a repeated `Drop`.
Reachable entirely from safe Rust via `catch_unwind` with element types whose `Drop` can panic.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
0.0.0-0 No fixed version published yet for sized-chunks. Pin to a known-safe version or switch to an alternative.