PT-2026-84131 · Crates.Io · Rtrb
Published
2026-08-04
·
Updated
2026-08-04
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
ReadChunk::commit and ReadChunk::commit all drop the committed elements
before advancing the consumer head. If an element's Drop panics during the
drop loop, head is never advanced, so the ring buffer still treats those slots
as holding live elements. When the RingBuffer is later dropped (it walks
head..tail and drops each slot), or a subsequent read chunk() / commit()
touches the same slots, the already-dropped elements are dropped a second time —
a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust.Mitigation
Update to 0.3.5 (0.3.x line) or 0.4.0. Note that 0.4.0 contains a behavior
change in
is abandoned(), so users on 0.3.x should prefer 0.3.5. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rtrb