VDB
Sign up

RUSTSEC-2026-0282

Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics

Details

Shrinking an `AlignedBox<[T]>` takes ownership of the buffer out of `self.container` with `ManuallyDrop::take`, destroys the elements past the new length, and only then commits the new `Box` back into `self.container`. `ManuallyDrop::take` moves ownership but not the bits, so until that commit `self.container` still points at the original buffer.

`T::drop` runs inside the destruction loop and is user code — `T` carries no bound that would exclude a panicking `Drop`. If it unwinds, the commit is skipped and `self.container` is left pointing at the buffer whose tail has already been destroyed. `AlignedBox`'s own destructor then reconstructs a `Box` from that pointer, drops every element again and deallocates — a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust.

Growing the slice destroys nothing and is unaffected, as is `realloc_with_value`, which requires `T: Copy` and therefore a `Drop` that cannot run.

## Mitigation

Update to 0.3.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/aligned_box
Introduced in: 0.0.0-0Fixed in: 0.3.1

Upgrade aligned_box to 0.3.1 or newer (ecosystem crates.io).

References