RUSTSEC-2026-0274
Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics
Details
`ReadChunk::commit` and `ReadChunk::commit_all` drop the committed elements before advancing the consumer head. If an element's `Drop` panics during the drop loop, `head` is never advanced, so the ring buffer still treats those slots as holding live elements. When the `RingBuffer` is later dropped (it walks `head..tail` and drops each slot), or a subsequent `read_chunk()` / `commit()` touches the same slots, the already-dropped elements are dropped a second time — a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust.
## Mitigation
Update to 0.3.5 (0.3.x line) or 0.4.0. Note that 0.4.0 contains a behavior change in `is_abandoned()`, so users on 0.3.x should prefer 0.3.5.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 0.3.5Upgrade rtrb to 0.3.5 or newer (ecosystem crates.io).