PT-2026-105964 · Crates.Io · Ringbuf

Publicado

2026-09-21

·

Atualizado

2026-09-21

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Consumer::skip() and Consumer::clear() are not panic-safe. They drop the consumed elements in place and only afterwards call advance read index() to move the ring buffer's read index past them. If an element's Drop panics mid-loop, advance read index() is never reached, so the read index still points at the already-dropped elements. When the ring buffer is later dropped, its destructor re-visits those slots and drops the same elements a second time — a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust, confirmed under AddressSanitizer.
Consumer::clear() delegates to Consumer::skip(self.len()), so both share the same root cause and the same fix.

Mitigation

Update to 0.5.2 or later (fixed in agerasev/ringbuf#60).
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

RUSTSEC-2026-0293

Produtos afetados

Ringbuf