RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0267

Panic-safety unsoundness in BitVecCore::clear (double-free / use-after-free)

Reported
Issued
Package
stable-vec (crates.io)
Type
INFO Unsound
Categories
Keywords
#panic-safety #memory-safety #use-after-free #double-free
Aliases
References
Patched
  • >=0.4.3
Affected Functions
Version
stable_vec::BitVecCore::clear
  • <0.4.3

Description

BitVecCore::clear drops every occupied element with drop_in_place and only afterwards clears the occupancy bits and resets len. If an element's Drop panics, those metadata updates are skipped, so the slot of the already-dropped element stays marked as occupied. BitVecCore::drop calls clear() again, visits the same slot, and drops the element a second time — a double-free / use-after-free reachable from safe Rust.

Reachable via the public StableVec::clear and ExternStableVec::clear, which delegate to BitVecCore::clear.

Impact

Reachable entirely from safe Rust via catch_unwind with element types whose Drop can panic. Confirmed under AddressSanitizer on 0.4.2.

Fix

Fixed in stable-vec 0.4.3 by removing each element via remove_at, which clears the occupancy bit before taking the value out.

Release 0.4.3 also fixes several other panic-safety issues found by the maintainer; see GHSA-mr2v-63pc-gmr4 and the 0.4.3 changelog for the full list.

Advisory available under CC0-1.0 license.