RUSTSEC-2026-0282
Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics
Details
Shrinking an `AlignedBox<[T]>` takes ownership of the buffer out of `self.container` with `ManuallyDrop::take`, destroys the elements past the new length, and only then commits the new `Box` back into `self.container`. `ManuallyDrop::take` moves ownership but not the bits, so until that commit `self.container` still points at the original buffer.
`T::drop` runs inside the destruction loop and is user code — `T` carries no bound that would exclude a panicking `Drop`. If it unwinds, the commit is skipped and `self.container` is left pointing at the buffer whose tail has already been destroyed. `AlignedBox`'s own destructor then reconstructs a `Box` from that pointer, drops every element again and deallocates — a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust.
Growing the slice destroys nothing and is unaffected, as is `realloc_with_value`, which requires `T: Copy` and therefore a `Drop` that cannot run.
## Mitigation
Update to 0.3.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 0.3.1Upgrade aligned_box to 0.3.1 or newer (ecosystem crates.io).